D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to r
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows att
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live vi
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementat
FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video
Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video st
A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arb
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an att
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attacke
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrar
A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allow
A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af447
A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticate
A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnera
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-w
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU mod
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/
A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59
A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing
Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to eleva
Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance whic
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows
A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9.
The privileged user could log in without sufficient credentials after enabling an application protocol. This security is
Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hit
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. Th
An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does no
Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android
Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack
The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an a
The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may all
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identifi
An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Acc
Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models
The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to a
The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network ac
# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started