IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauth
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, an
A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller o
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(
OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c
Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had c
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allow
A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content"
In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D
Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to
A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file
A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of th
A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<ap
In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/log
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t
Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacke
A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/openc
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragMod
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.
Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a
Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to
Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navi
Inappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker t
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attack
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attack
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's
A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of
Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authentica
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ads
A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earl
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced
Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to by
Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypas
Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and ano
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see informat
Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped A
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started