Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 65/134
8.1
CVE-2025-25950

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Info

8.1
CVE-2025-2280

Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an au

8.1
CVE-2024-44313

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which

8.1
CVE-2025-30735

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page a

8.1
CVE-2025-33072

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

8.1
CVE-2025-43586

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access

8.1
CVE-2023-47294

An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, l

8.1
CVE-2025-50060

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a

8.1
CVE-2025-50105

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administra

8.1
CVE-2025-27215

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast

8.1
CVE-2025-55741

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 a

8.1
CVE-2024-46916

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys

8.1
CVE-2025-56274

SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows

8.1
CVE-2025-59333

The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-s

8.1
CVE-2025-59943

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e

8.1
CVE-2025-62509

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version

8.1
CVE-2025-62510

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0

8.1
CVE-2025-61763

Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.

8.1
CVE-2025-57489

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privile

8.1
CVE-2025-65594

OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privil

8.0
CVE-2025-20229

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2

8.0
CVE-2025-52289

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg

8.0
CVE-2025-48860

A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) att

8.0
CVE-2025-64660

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne

7.9
CVE-2025-49707

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

7.8
CVE-2024-35177

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin

7.8
CVE-2025-21359

Windows Kernel Security Feature Bypass Vulnerability

7.8
CVE-2024-9157

** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics

7.8
CVE-2025-24173

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.

7.8
CVE-2025-1865

The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges

7.8
CVE-2025-27744

Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

7.8
CVE-2024-49842

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

7.8
CVE-2025-21469

Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.

7.8
CVE-2025-21470

Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.

7.8
CVE-2025-47161

Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24917

In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could

7.8
CVE-2024-53010

Memory corruption may occur while attaching VM when the HLOS retains access to VM.

7.8
CVE-2025-32714

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-47962

Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-27689

Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged at

7.8
CVE-2025-23365

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-pr

7.8
CVE-2025-47993

Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-50777

The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Acc

7.8
CVE-2025-27062

Memory corruption while handling client exceptions, allowing unauthorized channel access.

7.8
CVE-2025-53729

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49692

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges local

7.8
CVE-2025-54098

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-10491

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t

7.8
CVE-2025-43204

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to b

7.8
CVE-2025-43340

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started