A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Tr
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Ac
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The suppor
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user gr
A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership v
A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the func
Windows NTFS Elevation of Privilege Vulnerability
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and R
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects
An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, m
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record th
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3,
A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different o
A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown fun
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1
A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an un
Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /con
A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component G
A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.
A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator o
JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipst
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sectio
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that
A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of th
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-2
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all
A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information dis
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Ne
This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that c
A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component U
A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.7.2,
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the
Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicatio
Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow a d
A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an unknown part of the fil
conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Be
A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database con
KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join yo
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started