The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.
The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all
The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in a
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of da
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Ex
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and includi
The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all version
The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and
The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscri
An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Sma
An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplin
Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control wh
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to
The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remot
The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthoriz
The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulne
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 p
Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when cre
The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers t
The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information
An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Manageme
An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara R
An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipa
An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management
An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management Sy
An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management Sy
An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management
An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management
Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the publi
A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0,
ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files
A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 202410
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started