Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 19/62
7.2
CVE-2026-46922

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.2
CVE-2026-0283

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a

7.2
CVE-2026-60153

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported version

7.2
CVE-2026-60335

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.2
CVE-2026-60396

Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected ar

7.2
CVE-2026-60918

Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Sup

7.2
CVE-2026-60925

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

7.2
CVE-2026-61094

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve

7.2
CVE-2026-61285

Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operat

7.2
CVE-2026-60883

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleCode). Supported

7.2
CVE-2026-70861

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Common Obj

7.1
CVE-2026-1264

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0

7.1
CVE-2026-34472

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows u

7.1
CVE-2025-13030

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image

7.1
CVE-2026-24090

Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.

7.1
CVE-2026-50451

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized at

7.1
CVE-2024-34268

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow

7.1
CVE-2026-60623

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff

7.1
CVE-2026-60908

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Suppor

7.1
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colle

7.1
CVE-2025-71409

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages

7.1
CVE-2026-19908

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers

7.1
CVE-2026-60781

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi

7.1
CVE-2026-70806

Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Support

7.0
CVE-2026-46999

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery

7.0
CVE-2026-60705

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

7.0
CVE-2026-60902

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxedo). Supported vers

6.9
CVE-2026-32041

OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing bro

6.9
CVE-2026-55529

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts

6.8
CVE-2025-65731

An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacke

6.8
CVE-2025-32063

There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens d

6.8
CVE-2026-28450

OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap

6.8
CVE-2026-32291

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ

6.8
CVE-2026-22174

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback

6.8
CVE-2026-1724

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.1

6.8
CVE-2026-42312

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API

6.8
CVE-2026-50507

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security f

6.8
CVE-2026-59804

Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat

6.8
CVE-2026-47837

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri

6.7
CVE-2025-30650

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a

6.7
CVE-2026-42176

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat

6.7
CVE-2026-61176

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

6.5
CVE-2022-50979

An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr

6.5
CVE-2022-50980

A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre

6.5
CVE-2026-28352

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers

6.5
CVE-2026-29606

OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al

6.5
CVE-2025-13778

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AW

6.5
CVE-2026-31846

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 a

6.5
CVE-2026-33159

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R

6.5
CVE-2026-3527

Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Config

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started