When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functiona
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operatio
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera
Azure Networking Elevation of Privilege Vulnerability
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows at
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1
Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions pri
Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Accou
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Acces
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wil
An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) S
Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setU
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonom
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, m
This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7
A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS S
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDe
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not prop
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeControlle
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE
Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.
Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a craft
An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started