A vulnerability, which was classified as problematic, was found in juzaweb CMS up to 3.4.2. This affects an unknown part
A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability
A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerabili
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin
An improper access control vulnerability [CWE-284] in FortiIsolator version 2.4.4, version 2.4.3, 2.3 all versions loggi
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unk
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se
A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the f
A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical
A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in t
A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patien
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endp
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST A
The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp
A security flaw has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This
A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Execut
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticat
In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).
A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur
A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is som
A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1
The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the d
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.
A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so
A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte
open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reac
An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock Ro
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti
A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's file
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server
Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. Th
A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. Thi
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.
In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started