Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Info
Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an au
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page a
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access
An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, l
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administra
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 a
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys
SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-s
phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0
Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privile
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privil
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg
A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) att
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin
Windows Kernel Security Feature Bypass Vulnerability
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.
The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges
Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged at
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-pr
Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Acc
Memory corruption while handling client exceptions, allowing unauthorized channel access.
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges local
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to b
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started