The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ven
The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, in
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.
Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an auth
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An a
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced post
Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to poten
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a
An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a
An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the
Improper access control for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated u
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthent
A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authent
Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages
A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with onl
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an inter
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an inter
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an inter
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not ha
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions th
A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enab
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.
Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to ope
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.
A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management Syste
Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 20
Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize req
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access t
A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown
A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part
D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown
A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects
A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknow
A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown functi
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system.
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by thi
A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability i
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P
The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu
The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi
The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Informa
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started