Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported vers
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to cha
phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlatta
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impac
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability whi
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, under iMessage `groupPolicy=allowlist`, group authoriza
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner re
OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live Event
Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to byp
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS
BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi
DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged us
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteS
A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some
Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigati
An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App:
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authen
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent
Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The su
Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Orde
Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Orde
Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The
Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). S
Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attacker
A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move
Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a
A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started