SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue
A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown func
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u
The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori
Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publ
The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack
Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows
Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac
The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that
DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hos
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate p
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoi
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo
APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi
changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke
phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated att
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers
Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remot
APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso
The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present at
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started