Threats Tagged 'cwe-284'
View all threats tagged with 'cwe-284'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-284'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-77252 is an improper access control vulnerability in sooperset's mcp-atlassian server affecting versions prior to 0.22.0. It allows a caller to override administrator-configured allowlists for projects and spaces filters, enabling searches outside intended boundaries when Atlassian credentials permit. This flaw is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 09/22/2026, 17:54:02 UTC Added: 09/22/2026, 18:03:26 UTC |
Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*. Join the discussion | CVE Database V5 | 09/22/2026, 17:50:22 UTC Added: 09/22/2026, 18:03:27 UTC |
The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set grants allow-check to the webview, any XSS in the app frontend can invoke this command and bypass the only anti-rollback protection the updater offers. Combined with another bug, this enables downgrade attacks without even needing to fake a higher version number. Join the discussion | CVE Database V5 | 09/22/2026, 17:16:25 UTC Added: 09/22/2026, 17:33:23 UTC |
Nuclei versions from 3.0.0 up to but not including 3.10.0 have an improper access control vulnerability in the workflow template loading path. This flaw allows untrusted unsigned workflows to bypass the file capability gate and read local files on the scanner host via file-protocol templates, even when file templates are not enabled. The issue affects CLI users running workflows with the -w option and SDK integrations that accept end-user workflows relying on default file-access restrictions. The vulnerability is fixed in version 3.10.0. Join the discussion | CVE Database V5 | 09/22/2026, 16:41:46 UTC Added: 09/22/2026, 16:48:28 UTC |
Nuclei versions from 3.0.0 up to but not including 3.10.0 contain an improper access control vulnerability in the nuclei/mysql JavaScript library. This flaw allows untrusted JavaScript templates to bypass local-file sandbox restrictions when the allowAllFiles MySQL DSN option is used, enabling arbitrary file reads via LOAD DATA LOCAL INFILE requests. The vulnerability affects both CLI and SDK deployments that accept untrusted templates. It is fixed in version 3.10.0. Join the discussion | CVE Database V5 | 09/22/2026, 16:27:59 UTC Added: 09/22/2026, 16:48:28 UTC |
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning user's allowed_ip_ranges against the trusted client address in warpgate-protocol-http/src/common.rs. An attacker holding a leaked, phished, or exfiltrated X-Warpgate-Token can therefore use it from a prohibited network location. Deployments without allowed_ip_ranges are unaffected, and HTTP target proxying plus SSH, MySQL, PostgreSQL, RDP, VNC, and Kubernetes paths do not accept this vulnerable HTTP token flow. This issue is fixed in version 0.27.3. Join the discussion | CVE Database V5 | 09/21/2026, 18:50:40 UTC Added: 09/21/2026, 19:02:22 UTC |
File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database. Join the discussion | CVE Database V5 | 09/21/2026, 15:25:33 UTC Added: 09/21/2026, 15:32:23 UTC |
0 The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings. Join the discussion | CVE Database V5 | 09/20/2026, 06:00:17 UTC Added: 09/20/2026, 06:32:09 UTC |
0 The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site. Join the discussion | CVE Database V5 | 09/20/2026, 06:00:17 UTC Added: 09/20/2026, 06:32:09 UTC |
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them. Join the discussion | CVE Database V5 | 09/19/2026, 06:00:17 UTC Added: 09/19/2026, 06:32:09 UTC |
Showing 1 to 10 of 1152 results