Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 92/134
7.4
CVE-2024-20952

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

7.4
CVE-2024-22234

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to bro

7.4
CVE-2024-20767 KEV

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could resu

7.4
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual

7.4
CVE-2024-21740

Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.

7.4
CVE-2024-36492

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of

7.4
CVE-2020-36838

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp

7.3
CVE-2024-0570

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code

7.3
CVE-2024-22415

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +

7.3
CVE-2024-0712

A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affect

7.3
CVE-2023-32544

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installe

7.3
CVE-2023-39244

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in

7.3
CVE-2024-26203

Azure Data Studio Elevation of Privilege Vulnerability

7.3
CVE-2024-21110

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

7.3
CVE-2023-40071

Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user t

7.3
CVE-2024-36438

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check

7.3
CVE-2024-7553

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underl

7.3
CVE-2024-38202

Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli

7.3
CVE-2023-31341

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacke

7.3
CVE-2024-8269

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user r

7.3
CVE-2024-36488

Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially ena

7.3
CVE-2023-51644

Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote a

7.3
CVE-2024-12233

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects

7.3
CVE-2024-43594

Microsoft System Center Elevation of Privilege Vulnerability

7.3
CVE-2024-49107

WmsRepair Service Elevation of Privilege Vulnerability

7.3
CVE-2024-13030

A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the fu

7.2
CVE-2023-46712

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 throug

7.2
CVE-2024-24386

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalp

7.2
CVE-2024-0795

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that wo

7.2
CVE-2024-28405

SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin

7.2
CVE-2024-29054

Microsoft Defender for IoT Elevation of Privilege Vulnerability

7.2
CVE-2024-29055

Microsoft Defender for IoT Elevation of Privilege Vulnerability

7.2
CVE-2022-37341

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware

7.2
CVE-2024-36537

Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain

7.2
CVE-2024-42776

Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

7.2
CVE-2024-47910

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Admini

7.1
CVE-2023-20587

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leadin

7.1
CVE-2024-25121

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO

7.1
CVE-2023-33875

Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 m

7.1
CVE-2023-39941

Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to pote

7.1
CVE-2023-6259

Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Re

7.1
CVE-2024-0551

Enable exports of the database and associated exported information of the system via the default user role. The attacked

7.1
CVE-2024-36989

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a lo

7.1
CVE-2024-51995

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specif

7.1
CVE-2024-2315

APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploita

7.1
CVE-2024-49049

Visual Studio Code Remote Extension Elevation of Privilege Vulnerability

7.0
CVE-2024-20657

Windows Group Policy Elevation of Privilege Vulnerability

7.0
CVE-2022-37410

Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user

7.0
CVE-2024-34725

In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. Thi

7.0
CVE-2024-9576

Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the net

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started