Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be a
A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadO
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be a
hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una
The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7
FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a
Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to
Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is gi
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST
Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil
A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper A
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.t
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started