Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privil
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locall
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privilege
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil
This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and i
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privi
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to ex
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This i
An improper access control vulnerability may allow privilege escalation.This issue affects: * ELI 380 Resting Elect
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor
An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna
A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc
Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Mi
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qu
Improper Access Controls allows access to protected views.
Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu
an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, the
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac
Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sen
An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a l
An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream.
An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a n
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that
A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availab
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file c
Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens
Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf
Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen
Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started