Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occur
Loftware Spectrum through 4.6 has unprotected JMX Registry.
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem
TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can chan
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitr
eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object M
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 p
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privil
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, wh
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated at
Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Or
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.F
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Suppo
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.
A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality o
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management Syst
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth()
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Azure Stack Hub Elevation of Privilege Vulnerability
In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrar
MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, ar
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentia
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass
code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because t
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrati
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access cont
TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficient
An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to t
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and
Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (
Azure CycleCloud Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started