Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete inst
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GL
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachmen
An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and acce
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Comm
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthe
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and exp
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v202310
Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows rem
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access t
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to b
free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerabi
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/ap
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, ma
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS T
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious a
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is pub
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote att
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U
Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.30 a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Financial Services Transaction Filtering product of Oracle Financial Services Applications (
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started