Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to bro
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could resu
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual
Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of
The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +
A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affect
Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installe
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in
Azure Data Studio Elevation of Privilege Vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user t
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underl
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli
Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacke
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user r
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially ena
Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote a
A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects
Microsoft System Center Elevation of Privilege Vulnerability
WmsRepair Service Elevation of Privilege Vulnerability
A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the fu
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 throug
An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalp
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that wo
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware
Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Admini
Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leadin
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO
Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 m
Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to pote
Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Re
Enable exports of the database and associated exported information of the system via the default user role. The attacked
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a lo
Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specif
APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploita
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the net
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started