Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 66/134
7.8
CVE-2025-55694

Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-58714

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privil

7.8
CVE-2025-58724

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59199

Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locall

7.8
CVE-2025-59201

Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privilege

7.8
CVE-2025-59230 KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges

7.8
CVE-2025-59494

Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-61156

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil

7.8
CVE-2025-43407

This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and i

7.8
CVE-2025-43476

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom

7.8
CVE-2025-59512

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privi

7.8
CVE-2025-60705

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges

7.8
CVE-2025-37155

A vulnerability in the SSH restricted shell interface of the network management services allows improper access control

7.8
CVE-2025-61229

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to ex

7.8
CVE-2025-59517

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-62474

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges

7.8
CVE-2025-64673

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-64669

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

7.7
CVE-2025-23083

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This i

7.7
CVE-2022-26389

An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Elect

7.7
CVE-2025-1259

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been

7.7
CVE-2025-6741

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor

7.7
CVE-2025-4962

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna

7.7
CVE-2025-5962

A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc

7.7
CVE-2025-59500

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network

7.6
CVE-2025-24885

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Mi

7.6
CVE-2025-43862

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify

7.6
CVE-2025-46619

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that

7.6
CVE-2025-24857

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qu

7.5
CVE-2024-40749

Improper Access Controls allows access to protected views.

7.5
CVE-2024-13240

Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu

7.5
CVE-2025-0744

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic

7.5
CVE-2025-0745

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic

7.5
CVE-2024-57433

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, the

7.5
CVE-2024-56889

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth

7.5
CVE-2025-26616

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera

7.5
CVE-2024-36259

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac

7.5
CVE-2025-25381

Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sen

7.5
CVE-2025-25500

An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a l

7.5
CVE-2025-30141

An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream.

7.5
CVE-2025-30140

An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It

7.5
CVE-2025-29810

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a n

7.5
CVE-2025-30707

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions

7.5
CVE-2025-30728

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that

7.5
CVE-2025-32470

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availab

7.5
CVE-2025-45237

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file c

7.5
CVE-2025-45608

Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens

7.5
CVE-2025-45609

Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf

7.5
CVE-2025-45610

Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen

7.5
CVE-2025-45613

Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started