Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 14/62
8.1
CVE-2026-60462

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.1
CVE-2026-60543

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions t

8.1
CVE-2026-60621

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Th

8.1
CVE-2026-60653

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.1
CVE-2026-60670

Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System A

8.1
CVE-2026-60979

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported ve

8.1
CVE-2026-61074

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: eProcureme

8.1
CVE-2026-61092

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).

8.1
CVE-2026-61106

Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.

8.1
CVE-2026-61137

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th

8.1
CVE-2026-61163

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.1
CVE-2026-61170

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that

8.1
CVE-2026-61225

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Cor

8.1
CVE-2026-62547

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp

8.1
CVE-2026-67610

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi

8.1
CVE-2026-24079

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

8.1
CVE-2026-60742

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). S

8.1
CVE-2026-60831

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Su

8.1
CVE-2026-61307

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common

8.1
CVE-2026-70805

Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Managemen

8.1
CVE-2026-70924

Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).

8.1
CVE-2026-71068

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

8.1
CVE-2026-65105

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the

8.1
CVE-2026-77977

Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive

8.0
CVE-2026-27509

Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat

8.0
CVE-2026-0204

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access

8.0
CVE-2026-9212

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network

8.0
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using

8.0
CVE-2026-60652

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati

8.0
CVE-2026-15581

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b

8.0
CVE-2026-82282

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to acce

7.8
CVE-2026-24062

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signatu

7.8
CVE-2026-33788

A Missing Authentication for Critical Function vulnerability in the Flexible PIC Concentrators (FPCs) of Juniper Network

7.8
CVE-2026-26159

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker t

7.8
CVE-2026-26160

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker t

7.8
CVE-2026-41477

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex

7.8
CVE-2026-0247

Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack

7.8
CVE-2026-50512

Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges

7.8
CVE-2026-9045

During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag

7.8
CVE-2026-50333

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privilege

7.8
CVE-2026-60600

Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The

7.8
CVE-2026-59913

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti

7.8
CVE-2026-42976

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-61356

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate

7.8
CVE-2026-61364

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate

7.8
CVE-2026-61365

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate

7.8
CVE-2026-61367

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate

7.8
CVE-2026-62777

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privile

7.7
CVE-2025-1272

The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started