Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated re
Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when expli
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the appli
Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application
Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attack
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store
Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe
Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH),
Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve
This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i
A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive inf
The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R
Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Acce
WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows
Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level
A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNe
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginm
The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication contr
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate
JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotate
An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated atta
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t
An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirement
Vulnerability in the JD Edwards EnterpriseOne Advanced Pricing - Procurement product of Oracle JD Edwards (component: Ad
Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation).
Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started