Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access t
Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability wi
ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10
Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potent
Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper a
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service vi
A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Applian
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected a
Windows Initial Machine Configuration Elevation of Privilege Vulnerability
Improper access control for some Intel(R) Arc(TM) Pro Graphics for Windows drivers before version 31.0.101.5319 may allo
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web modul
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0
Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may
Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticat
Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to pote
Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may a
Proxy Driver Spoofing Vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell re
Visual Studio Elevation of Privilege Vulnerability
Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance f
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privilege
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent
Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to
Visual Studio Elevation of Privilege Vulnerability
Improper access control in some JAM STAPL Player software before version 2.6.1 may allow an authenticated user to potent
Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user t
Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00
Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability
Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local a
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, perso
pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An
In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permission
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul
A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access con
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to im
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.
An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DL
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbit
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper in
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). S
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-ch
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Expos
A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected i
Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerabilit
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started