Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Manag
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property th
An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be
Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to
Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to po
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after
An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execut
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 1
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and all
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token me
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 a
The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implement
A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users
SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_re
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before v
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remot
Microsoft SQL Server Elevation of Privilege Vulnerability
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowi
A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user
PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak c
BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows netwo
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an auth
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn
A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may a
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invit
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonom
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounti
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin
phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumbe
Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa
DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an at
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
Memory corruption in Automotive Multimedia due to improper access control in HAB.
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware
The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confus
An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufac
An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started