Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr
OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and electio
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat
A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Clie
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web
The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to ve
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password res
HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri
FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported ve
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/miner
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access t
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exist
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a mi
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modif
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endp
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control
Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate p
Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges
Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Other). The
Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). S
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported
Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench)
Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a us
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper author
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started