Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). T
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcur
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain a
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import modul
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by ma
The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remot
Delta Electronics DIAView has multiple vulnerabilities.
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to r
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthent
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 and below,
IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to di
Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network p
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in
A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated a
An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password b
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardc
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication b
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus expose
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotel
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to e
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Gene
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows u
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a pri
Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unau
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and co
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessibl
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NV
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remot
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracl
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers c
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 1,534 CVE records associated with CWE-306 in our database. Of these, 549 are critical severity, 593 are high severity, and 232 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started