Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 11/62
8.8
CVE-2026-60872

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

8.8
CVE-2026-60890

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-60897

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-60898

Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-60901

Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-60920

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supporte

8.8
CVE-2026-60924

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

8.8
CVE-2026-60932

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup

8.8
CVE-2026-60952

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)

8.8
CVE-2026-60989

Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). S

8.8
CVE-2026-61010

Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operat

8.8
CVE-2026-61098

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

8.8
CVE-2026-61099

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

8.8
CVE-2026-61110

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version

8.8
CVE-2026-61121

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th

8.8
CVE-2026-61127

Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solut

8.8
CVE-2026-61149

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.8
CVE-2026-61168

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

8.8
CVE-2026-61179

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

8.8
CVE-2026-61180

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr

8.8
CVE-2026-61243

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffin

8.8
CVE-2026-61311

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported

8.8
CVE-2026-61320

Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported ver

8.8
CVE-2026-61322

Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions

8.8
CVE-2026-62447

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versi

8.8
CVE-2026-62464

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

8.8
CVE-2026-62476

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

8.8
CVE-2026-62478

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

8.8
CVE-2026-62496

Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Suppor

8.8
CVE-2026-62498

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Sup

8.8
CVE-2026-62534

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Suppo

8.8
CVE-2026-60373

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-60439

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-61246

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.8
CVE-2026-7187

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionalit

8.8
CVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on

8.8
CVE-2026-12562

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full

8.8
CVE-2026-60009

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every

8.8
CVE-2026-64921

Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate pri

8.8
CVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio

8.8
CVE-2026-66875

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range

8.8
CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte

8.8
CVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on t

8.8
CVE-2026-73673

Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthentic

8.8
CVE-2026-60716

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported

8.8
CVE-2026-60722

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported

8.8
CVE-2026-60731

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi

8.8
CVE-2026-60751

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions th

8.8
CVE-2026-60879

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager).

8.8
CVE-2026-60967

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision). Supported ver

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started