Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corruptin
In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory.
Remote Desktop Client Remote Code Execution Vulnerability
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints a
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana
Dell InsightIQ, version 5.0, contains an improper access control vulnerability. A remote low privileged attacker could p
A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Rea
OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observ
Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted lib
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v
Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to poten
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to by
Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share cli
In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that c
Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow a
Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potent
Microsoft SharePoint Elevation of Privilege Vulnerability
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing s
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attacke
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions
The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of
The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshar
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Qua
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the to
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low p
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is create
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthen
Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providin
Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be ac
Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to e
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4
Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolk
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on s
Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior
Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacki
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error.
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started