An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board leve
Improper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentiall
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) fe
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6.
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This i
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may aff
A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and clas
A vulnerability classified as problematic has been found in Amcrest IP2M-841B, IP2M-841W, IPC-IP2M-841B, IPC-IP3M-943B,
A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so
Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged
A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access t
A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attac
Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at je
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenti
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow
The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow a
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to loca
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing c
A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by
Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 al
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to
Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. In affected versions an attacker with the ab
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be retu
Windows Remote Desktop Services Tampering Vulnerability
A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allow
Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x
Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially ena
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowli
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an
A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vul
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the com
A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vu
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 o
The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder c
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Ad
In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclos
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started