Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 17/62
7.5
CVE-2026-60604

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The

7.5
CVE-2026-60605

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Higher Ed Statist

7.5
CVE-2026-60619

Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting an

7.5
CVE-2026-60689

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

7.5
CVE-2026-60704

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

7.5
CVE-2026-60855

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers

7.5
CVE-2026-60859

Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: Internal Operations). Supported vers

7.5
CVE-2026-60894

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers

7.5
CVE-2026-60927

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

7.5
CVE-2026-60931

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)

7.5
CVE-2026-60988

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation

7.5
CVE-2026-61141

Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supp

7.5
CVE-2026-61158

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

7.5
CVE-2026-61188

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In

7.5
CVE-2026-62493

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported v

7.5
CVE-2026-65319

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated at

7.5
CVE-2026-5057

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attacke

7.5
CVE-2026-54365

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe

7.5
CVE-2026-67349

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm

7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s

7.5
CVE-2026-15978

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end

7.5
CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu

7.5
CVE-2026-68578

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p

7.5
CVE-2026-69091

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only

7.5
CVE-2026-71241

Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi

7.5
CVE-2026-61891

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin

7.5
CVE-2026-48911

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug

7.5
CVE-2026-8446

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP)

7.5
CVE-2026-69111

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers

7.5
CVE-2026-53977

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to termi

7.5
CVE-2026-53985

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's serv

7.5
CVE-2026-70559

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t

7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version

7.5
CVE-2026-72586

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que

7.5
CVE-2026-72688

A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at

7.5
CVE-2026-72871

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith

7.5
CVE-2026-72605

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary

7.5
CVE-2026-73246

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest

7.5
CVE-2026-75479

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows un

7.5
CVE-2026-60765

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions th

7.5
CVE-2026-60769

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support

7.5
CVE-2026-60975

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported ve

7.5
CVE-2026-70930

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

7.5
CVE-2026-70973

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

7.5
CVE-2026-19875

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abu

7.5
CVE-2026-76355

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edg

7.5
CVE-2026-14952

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /F

7.5
CVE-2025-52182

The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.

7.5
CVE-2026-49217

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mail

7.5
CVE-2026-75501

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote a

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started