A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti
A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of
Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported ver
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring)
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitra
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a mi
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering
OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi
A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat
Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modif
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a use
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could downloa
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentic
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of th
A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of th
A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown func
The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific condit
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacke
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart
Vulnerability in the PeopleSoft Enterprise FIN Pay/Bill Management product of Oracle PeopleSoft (component: Paybill Mana
Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized mo
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote
FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessi
The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c
The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote at
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al
A specific administrative endpoint notifications is accessible without proper authentication.
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started