An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenti
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_
Azure Compute Gallery Elevation of Privilege Vulnerability
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Da
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the fl
A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS So
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in th
In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions
Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote
Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.
Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access c
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged us
PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that
An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher
An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 al
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would al
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in t
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potent
Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service
RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the H
Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerab
OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observ
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and mor
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game serv
A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unk
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 all
A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulne
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an at
Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly
A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown f
A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects a
A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerab
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1
A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affecte
A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected b
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnera
A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected b
A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulner
A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started