Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 90/134
7.8
CVE-2024-34099

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability

7.8
CVE-2023-43748

Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authentica

7.8
CVE-2023-52711

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections

7.8
CVE-2023-52712

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections

7.8
CVE-2022-48683

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may

7.8
CVE-2024-37289

An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on

7.8
CVE-2024-39934

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup

7.8
CVE-2024-38100

Windows File Explorer Elevation of Privilege Vulnerability

7.8
CVE-2024-31320

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association withou

7.8
CVE-2024-40812

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPad

7.8
CVE-2024-41308

An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal enviro

7.8
CVE-2024-41309

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted termina

7.8
CVE-2024-38162

Azure Connected Machine Agent Elevation of Privilege Vulnerability

7.8
CVE-2024-38195

Azure CycleCloud Remote Code Execution Vulnerability

7.8
CVE-2024-38163

Windows Update Stack Elevation of Privilege Vulnerability

7.8
CVE-2024-26022

Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated us

7.8
CVE-2024-43492

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

7.8
CVE-2024-38016

Microsoft Office Visio Remote Code Execution Vulnerability

7.8
CVE-2024-43503

Microsoft SharePoint Elevation of Privilege Vulnerability

7.8
CVE-2024-43590

Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

7.8
CVE-2024-45334

Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that c

7.8
CVE-2024-43530

Windows Update Stack Elevation of Privilege Vulnerability

7.8
CVE-2024-49600

Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged att

7.8
CVE-2024-43600

Microsoft Office Elevation of Privilege Vulnerability

7.7
CVE-2024-24771

Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-e

7.7
CVE-2023-52367

Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may a

7.7
CVE-2024-45392

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficien

7.6
CVE-2023-50341

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated a

7.6
CVE-2024-4225

Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), b

7.6
CVE-2024-36443

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonym

7.6
CVE-2024-46607

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values a

7.6
CVE-2024-21195

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions

7.6
CVE-2024-56335

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve

7.5
CVE-2024-21644

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a spe

7.5
CVE-2023-49961

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead

7.5
CVE-2023-51065

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers

7.5
CVE-2023-51070

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers

7.5
CVE-2023-52114

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect

7.5
CVE-2023-52099

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulne

7.5
CVE-2023-52105

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect ava

7.5
CVE-2024-20932

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

7.5
CVE-2023-47034

A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.

7.5
CVE-2024-23331

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case

7.5
CVE-2023-44031

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitr

7.5
CVE-2024-20931

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

7.5
CVE-2023-52375

Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may a

7.5
CVE-2023-49545

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files

7.5
CVE-2022-47037

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCreden

7.5
CVE-2024-25736

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d

7.5
CVE-2024-27605

Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the sy

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started