Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 28/134
7.5
CVE-2026-35242

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.5
CVE-2026-35245

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.5
CVE-2026-35246

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.5
CVE-2026-35251

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.5
CVE-2026-22754

Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=

7.5
CVE-2026-40595

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c

7.5
CVE-2024-52911

Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is

7.5
CVE-2026-28930

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be a

7.5
CVE-2026-28965

A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able

7.5
CVE-2026-28974

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadO

7.5
CVE-2026-43652

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be a

7.5
CVE-2026-44478

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una

7.5
CVE-2026-32995

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7

7.5
CVE-2026-37235

FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T

7.5
CVE-2026-41006

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty

7.5
CVE-2026-39169

SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.

7.5
CVE-2026-41728

Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int

7.5
CVE-2026-41856

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on

7.5
CVE-2025-46315

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a

7.5
CVE-2026-50885

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to

7.5
CVE-2026-47261

Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is gi

7.5
CVE-2026-35269

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers

7.5
CVE-2026-35275

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported

7.5
CVE-2026-46791

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

7.5
CVE-2026-46934

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte

7.5
CVE-2026-46935

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte

7.5
CVE-2026-46957

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo

7.5
CVE-2026-46958

Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S

7.5
CVE-2026-46959

Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S

7.5
CVE-2026-46966

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level

7.5
CVE-2026-46971

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.5
CVE-2026-46974

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.5
CVE-2026-56082

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST

7.5
CVE-2026-56253

Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that

7.5
CVE-2026-52844

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat

7.5
CVE-2026-12490

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate

7.5
CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil

7.5
CVE-2026-51221

A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D

7.5
CVE-2026-55112

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper A

7.5
CVE-2026-24451

Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing

7.5
CVE-2026-24690

Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.

7.5
CVE-2026-25712

Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and

7.5
CVE-2026-27660

Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio

7.5
CVE-2026-27779

Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp

7.5
CVE-2026-58421

Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

7.5
CVE-2026-59720

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.t

7.5
CVE-2025-63579

Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu

7.5
CVE-2026-40452

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas

7.5
CVE-2026-35287

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita

7.5
CVE-2026-46941

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started