A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functio
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physi
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the com
Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Support
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/Aut
Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the rever
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met
Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/
Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuari
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the Th
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are autom
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R2
A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Auto
mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerabili
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administr
UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of Sm
Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a den
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr
Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perf
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Na
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulne
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rust
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access co
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site s
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su
Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard
Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started