Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta
WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication byp
NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not
ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email
@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT obj
Frequently Asked Questions
What is CWE-302?
CWE-302 (CWE-302) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-302?
There are 13 CVE records associated with CWE-302 in our database. Of these, 1 are critical severity, 5 are high severity, and 5 are medium severity.
How can I protect against CWE-302 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-302 using AI-powered security agents.
Detect CWE-302 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-302 vulnerabilities across your infrastructure.
Get Started