OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in wh
Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe
NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A succ
DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is r
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is
Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated
LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth c
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacke
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows rem
Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera foo
Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remot
Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers
Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthentica
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUX
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrie
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener acc
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss:/
JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remo
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in
Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all
OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx
The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualB
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requirin
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Mani
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints.
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose informati
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediatio
Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic au
Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Confi
Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthentica
Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that
The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started