A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a
A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0.
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue af
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function Uploa
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted c
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are aff
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supporte
Improper access control in firmware for some Intel(R) Thunderbol(TM) Controllers versions before 41 may allow a privileg
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).
Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supporte
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager coul
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permission
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend develo
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly res
Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel a
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080,
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top
A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 25
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR
A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco I
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Service Gateway). Supported versions t
A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Def
A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Def
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user r
Skype for Business Information Disclosure Vulnerability
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, i
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentia
Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potent
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ven
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gai
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ven
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started