Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-284

MITRE ↗

CWE-284

877
CRITICAL
2,593
HIGH
2,830
MEDIUM
289
LOW
6,696 CVEs · Page 93/134
7.0
CVE-2024-47975

Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access t

6.9
CVE-2024-42033

Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability wi

6.8
CVE-2023-51751

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10

6.8
CVE-2023-32647

Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potent

6.8
CVE-2024-22459

Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper a

6.8
CVE-2024-24487

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service vi

6.8
CVE-2024-34404

A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Applian

6.8
CVE-2024-5430

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0

6.8
CVE-2024-41905

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a

6.8
CVE-2024-38223

Windows Initial Machine Configuration Elevation of Privilege Vulnerability

6.8
CVE-2024-32044

Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allo

6.8
CVE-2024-22067

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web modul

6.7
CVE-2023-32479

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0

6.7
CVE-2023-22311

Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may

6.7
CVE-2023-25174

Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticat

6.7
CVE-2023-31271

Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to pote

6.7
CVE-2023-39432

Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may a

6.7
CVE-2024-26234

Proxy Driver Spoofing Vulnerability

6.7
CVE-2024-21107

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

6.7
CVE-2024-21828

Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow

6.7
CVE-2024-22026

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell re

6.7
CVE-2024-29060

Visual Studio Elevation of Privilege Vulnerability

6.7
CVE-2024-21302

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance f

6.7
CVE-2024-39580

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privilege

6.7
CVE-2024-34543

Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent

6.7
CVE-2024-47976

Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to

6.7
CVE-2024-49044

Visual Studio Elevation of Privilege Vulnerability

6.7
CVE-2024-29077

Improper access control in some JAM STAPL Player software before version 2.6.1 may allow an authenticated user to potent

6.7
CVE-2024-34022

Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user t

6.6
CVE-2023-27517

Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00

6.6
CVE-2023-40161

Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user

6.6
CVE-2024-26201

Microsoft Intune Linux Agent Elevation of Privilege Vulnerability

6.6
CVE-2024-24902

Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local a

6.5
CVE-2023-6733

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up

6.5
CVE-2024-21666

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, perso

6.5
CVE-2024-21667

pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An

6.5
CVE-2024-23675

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permission

6.5
CVE-2024-21653

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul

6.5
CVE-2024-1114

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function

6.5
CVE-2023-32333

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access con

6.5
CVE-2023-38263

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to im

6.5
CVE-2021-46903

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.

6.5
CVE-2024-23446

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DL

6.5
CVE-2024-1439

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbit

6.5
CVE-2024-0032

In multiple locations, there is a possible way to request access to directories that should be hidden due to improper in

6.5
CVE-2024-20929

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). S

6.5
CVE-2024-28120

codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-ch

6.5
CVE-2024-1668

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Expos

6.5
CVE-2024-2481

A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected i

6.5
CVE-2024-1144

Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerabilit

Frequently Asked Questions

What is CWE-284?

CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-284?

There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.

How can I protect against CWE-284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.

Detect CWE-284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.

Get Started