Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 87/134
9.8
CVE-2024-45522

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occur

9.8
CVE-2023-37234

Loftware Spectrum through 4.6 has unprotected JMX Registry.

9.8
CVE-2024-45489

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by

9.8
CVE-2024-42797

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem

9.8
CVE-2023-26770

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can chan

9.8
CVE-2024-10124

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitr

9.6
CVE-2023-50257

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object M

9.6
CVE-2024-5655

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 p

9.6
CVE-2024-6385

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p

9.6
CVE-2024-38164

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne

9.6
CVE-2024-38175

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta

9.6
CVE-2023-29121

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

9.4
CVE-2024-21767

A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.

9.3
CVE-2024-21364

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

9.1
CVE-2022-46025

Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers

9.1
CVE-2024-25106

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet

9.1
CVE-2023-51786

An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privil

9.1
CVE-2021-47155

The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, wh

9.1
CVE-2020-26942

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated at

9.1
CVE-2024-29866

Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Or

9.1
CVE-2024-27602

Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.F

9.1
CVE-2024-24486

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the

9.1
CVE-2024-21071

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Suppo

9.1
CVE-2024-31967

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.

9.1
CVE-2024-22187

A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality o

9.1
CVE-2024-28805

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

9.1
CVE-2024-42775

An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management Syst

9.1
CVE-2024-46627

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

9.0
CVE-2024-22206

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth()

9.0
CVE-2024-21376

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

9.0
CVE-2024-29990

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

9.0
CVE-2024-38220

Azure Stack Hub Elevation of Privilege Vulnerability

8.8
CVE-2023-50159

In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrar

8.8
CVE-2023-47867

MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect

8.8
CVE-2024-24824

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, ar

8.8
CVE-2024-25677

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly

8.8
CVE-2023-39425

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentia

8.8
CVE-2023-47422

An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.

8.8
CVE-2024-1675

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass

8.8
CVE-2024-25251

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

8.8
CVE-2024-25723

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t

8.8
CVE-2024-1632

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrati

8.8
CVE-2024-27497

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

8.8
CVE-2023-38946

An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access cont

8.8
CVE-2023-43318

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of

8.8
CVE-2024-28115

FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficient

8.8
CVE-2024-25501

An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to t

8.8
CVE-2023-49978

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and

8.8
CVE-2023-50702

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (

8.8
CVE-2024-29993

Azure CycleCloud Elevation of Privilege Vulnerability

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started