Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions t
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Th
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System A
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcureme
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).
Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Cor
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Su
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common
Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Managemen
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to acce
The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signatu
A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Network
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker t
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker t
Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack
Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privilege
Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privile
The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started