Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-303

MITRE ↗

CWE-303

10
CRITICAL
12
HIGH
8
MEDIUM
30 CVEs
10.0
CVE-2026-46595

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal

10.0
CVE-2026-46389

UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Co

9.8
CVE-2026-29515

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that all

9.8
CVE-2026-35579

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati

9.8
CVE-2026-59309

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n

9.4
CVE-2026-28446

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass

9.1
CVE-2026-33557

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare

9.1
CVE-2026-41103

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho

9.1
CVE-2026-50627

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok

9.1
CVE-2026-10050

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th

8.8
CVE-2025-4676

Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C

8.8
CVE-2026-0073

In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err

8.8
CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused

8.8
CVE-2026-50360

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate priv

8.8
CVE-2026-47300

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges

8.8
CVE-2026-49467

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0

8.1
CVE-2025-14510

Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi

8.1
CVE-2020-37094

EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to

8.1
CVE-2026-43640

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or

7.5
CVE-2026-33190

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D

7.3
CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file lite

7.3
CVE-2026-11430

Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu

6.7
CVE-2026-66028

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe

6.5
CVE-2019-25436

Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to

5.7
CVE-2026-27656

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate

5.6
CVE-2026-57852

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att

5.4
CVE-2026-0999

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restri

5.4
CVE-2026-8922

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key

5.3
CVE-2026-66411

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut

4.6
CVE-2026-32953

Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t

Frequently Asked Questions

What is CWE-303?

CWE-303 (CWE-303) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-303?

There are 30 CVE records associated with CWE-303 in our database. Of these, 10 are critical severity, 12 are high severity, and 8 are medium severity.

How can I protect against CWE-303 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-303 using AI-powered security agents.

Detect CWE-303 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-303 vulnerabilities across your infrastructure.

Get Started