DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named p
Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.
Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functio
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Son
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers t
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo
SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Un
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In s
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv
The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauth
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allo
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authent
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such a
Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive componen
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated u
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previo
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under uni
Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a secur
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au
ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload
Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentia
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a net
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that c
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its s
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can
OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable
A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can o
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Ac
Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are no
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started