An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability
Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3
Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version
Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap
FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end
Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro
A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u
FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible deb
Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Curso
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39,
A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A
TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic
TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service
Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated P
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass m
Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof`
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replic
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authentic
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth rang
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sens
RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint p
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to e
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc
A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead t
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started