Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Co
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that all
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass
A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate priv
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges
Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0
Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file lite
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe
Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restri
A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut
Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t
Frequently Asked Questions
What is CWE-303?
CWE-303 (CWE-303) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-303?
There are 30 CVE records associated with CWE-303 in our database. Of these, 10 are critical severity, 12 are high severity, and 8 are medium severity.
How can I protect against CWE-303 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-303 using AI-powered security agents.
Detect CWE-303 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-303 vulnerabilities across your infrastructure.
Get Started