Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop v
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the
Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of t
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this v
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confi
The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a m
gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` f
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Finance LOV). Supported ver
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Offer LOV). Supported versi
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim
An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.
An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of t
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases ho
The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to th
A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of Auto
The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could
ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could resu
An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacke
DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mis
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive
This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.
An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allow
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to
Improper Access Controls allows backend users to overwrite their username when disallowed.
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated at
fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--all
A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using
Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticat
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including
An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s
eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that c
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentiall
CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able t
An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unau
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started