Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instan
Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `
HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive a
bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnera
TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th
A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local
A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized us
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Soc
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21
Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). Th
Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dn
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware.
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen
The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done
Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat
A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker
Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.
The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user
The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attac
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exch
A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access
This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service ov
The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.
Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain
A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC too
A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s
Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the ex
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search ind
Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [All
GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships
Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelis
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rus
Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file upl
A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute a
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started