A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function sa
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown
The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, wa
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical
A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the compone
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper chec
A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sec
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 2
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An a
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL). Supported versions t
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Manage
Local File Inclusion via file:// URI in Migration Restore
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2
OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allo
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to e
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listin
Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()`
Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exis
Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, al
Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with rea
A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the
A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started