Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 22/62
5.3
CVE-2026-32962

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue

5.3
CVE-2026-8031

A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown func

5.3
CVE-2026-43881

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u

5.3
CVE-2026-31245

The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori

5.3
CVE-2026-45248

Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e

5.3
CVE-2026-45397

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /

5.3
CVE-2026-8737

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publ

5.3
CVE-2026-11848

The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una

5.3
CVE-2026-8694

Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack

5.3
CVE-2026-56299

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows

5.3
CVE-2026-56321

Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /

5.3
CVE-2026-54036

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en

5.3
CVE-2026-31983

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac

5.3
CVE-2026-61344

The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that

5.3
CVE-2026-55605

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hos

5.3
CVE-2026-57475

Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed

5.3
CVE-2026-56164 KEV

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate p

5.3
CVE-2026-45754

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1

5.3
CVE-2026-45755

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.

5.3
CVE-2026-47212

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1

5.3
CVE-2026-63098

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta

5.3
CVE-2025-68640

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T

5.3
CVE-2026-65014

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoi

5.3
CVE-2026-65012

InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo

5.3
CVE-2026-47769

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr

5.3
CVE-2026-66006

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs

5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi

5.3
CVE-2026-71203

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke

5.3
CVE-2026-75919

phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated att

5.3
CVE-2026-19441

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.

5.3
CVE-2026-69228

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot

5.3
CVE-2026-19853

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers

5.3
CVE-2026-79668

Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una

5.3
CVE-2026-80234

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remot

5.3
CVE-2026-80207

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso

5.3
CVE-2026-81664

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi

5.3
CVE-2026-82276

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec

5.1
CVE-2026-60569

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that

5.0
CVE-2026-2756

A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the

5.0
CVE-2026-4582

A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili

4.8
CVE-2026-32896

The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication

4.8
CVE-2026-57476

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio

4.8
CVE-2026-61247

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp

4.8
CVE-2026-66139

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

4.7
CVE-2026-19971

A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th

4.5
CVE-2026-3194

A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of

4.4
CVE-2026-54776

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,

4.4
CVE-2026-60884

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo

4.3
CVE-2025-15509

The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.

4.3
CVE-2026-13306

Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present at

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started