An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmw
Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially craft
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager versio
Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker
Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a ne
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2
Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent
Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Fun
A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9.
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth
A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit
A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewC
NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentic
In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing u
Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the fi
An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of r
An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authent
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload
The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. Th
IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session aut
A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60.
The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authenticatio
Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.
The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its
An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and Ex
A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain admin
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate pri
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o
A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIB
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-139
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. Thi
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This
A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0
An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated at
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started