Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-304

MITRE ↗

CWE-304

4
CRITICAL
7
HIGH
1
MEDIUM
12 CVEs
9.8
CVE-2026-30831

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1

9.6
CVE-2026-44547

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The

9.1
CVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val

9.1
CVE-2026-59564

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and th

8.8
CVE-2026-67351

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and sessio

8.8
CVE-2026-49467

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0

8.1
CVE-2026-42452

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v

8.1
CVE-2026-76207

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued befo

7.3
CVE-2026-40542

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-

7.3
CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized

7.3
CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate

6.4
CVE-2026-61143

Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: P

Frequently Asked Questions

What is CWE-304?

CWE-304 (CWE-304) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-304?

There are 12 CVE records associated with CWE-304 in our database. Of these, 4 are critical severity, 7 are high severity, and 1 are medium severity.

How can I protect against CWE-304 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-304 using AI-powered security agents.

Detect CWE-304 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-304 vulnerabilities across your infrastructure.

Get Started