Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 24/62
CVE-2026-11535

An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut

CVE-2026-50287

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a

CVE-2026-0647

An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability

CVE-2026-48989

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m

CVE-2026-12527

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3

CVE-2026-49357

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o

CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version

CVE-2026-13164

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap

CVE-2026-33543

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end

CVE-2026-4522

Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti

CVE-2026-54088

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

CVE-2026-43920

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch

CVE-2026-12819

Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro

CVE-2026-44949

A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0

CVE-2026-42331

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u

CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti

CVE-2026-53647

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser

CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP

CVE-2026-22096

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a

CVE-2026-6847

Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu

CVE-2026-10577

A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible deb

CVE-2026-61613

Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Curso

CVE-2026-57495

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39,

CVE-2026-12989

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at

CVE-2026-58071

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A

CVE-2025-15681

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic

CVE-2025-15683

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An

CVE-2026-18673

When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service

CVE-2026-71878

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated P

CVE-2026-9033

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active

CVE-2026-77644

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise

CVE-2026-76157

Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0

CVE-2026-15576

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass m

CVE-2026-48050

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof`

CVE-2026-48106

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replic

CVE-2026-78255

The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authentic

CVE-2026-78306

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth rang

CVE-2026-6017

Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sens

CVE-2026-78369

RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint p

CVE-2026-57909

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to e

CVE-2026-57910

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen

CVE-2026-65956

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API

CVE-2026-68929

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, th

CVE-2026-55678

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc

10.0
CVE-2024-39608

A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially

10.0
CVE-2025-24865

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an

10.0
CVE-2025-32433 KEV

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O

10.0
CVE-2025-34028 KEV

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta

10.0
CVE-2024-46506

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun

10.0
CVE-2025-36535

The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead t

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started