NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the aut
An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the a
Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects
A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat
Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without auth
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access an
The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could al
An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 -
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attac
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an
A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. Thi
The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na
Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Par
The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass
In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and
An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported version
WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator accou
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerabilit
Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbit
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager v
Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if co
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication fra
An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and
A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot
A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a
Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint tha
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started