FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbit
By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulner
Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Se
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati
An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious a
WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to conf
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup f
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read,
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, t
Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remo
Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability
Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This s
The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application prior to 20.0.2786 (VA an
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 2
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, u
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, al
Azure Entra ID Elevation of Privilege Vulnerability
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 154
Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support
Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and
MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is acc
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user acco
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started