Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to poten
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with
Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of o
A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerabili
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a
A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unaut
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unaut
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to Cross
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` U
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other grou
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all
Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca
The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to
Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing
Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privilege
The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unli
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment infor
The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improp
The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vu
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access contro
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allow
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playboo
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capab
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an inter
A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule r
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, start
A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their o
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vul
A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started