Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information
Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensit
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7
Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may a
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny se
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users
Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Databa
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit
Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover,
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary comma
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK B
Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download
The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to overrid
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation coul
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corru
Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res
Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the
An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in som
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of d
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.
Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce
Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local networ
TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying requ
ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed
AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arsh
Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an impro
mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper acces
2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., con
Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont
AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con
Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou
Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, mac
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.
A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1,
Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen
Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2.
Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attacke
Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started