Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Re
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15
This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service.
DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robo
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete
Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not exp
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish serv
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remo
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardle
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute ad
Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Mul
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application cons
An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escala
Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute
A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, A
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1
Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build
Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be cha
Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerabi
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/pr
Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.
Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An
GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performin
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining t
Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrat
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension betwee
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw
A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam S
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration fil
An issue in the login component (process_login.php) of Hotel Management System commit 79d688 allows attackers to authent
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially lea
An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an at
An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can dir
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started