CVE-2025-1701 is a high-severity vulnerability in the MIM Admin service. An attacker could exploit this vulnerability by
The wallet has an authentication bypass vulnerability that allows access to specific pages.
In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, re
The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are
A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing ser
An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR
An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta
An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man
An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i
A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi
An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.
An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI in
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers
An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 1
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging e
A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Li
Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authenticati
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the insta
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to pro
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 an
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated
The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modi
A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged u
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance vers
Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed
A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials c
The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal s
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session
The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "
The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/Clini
The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authent
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authen
Delta Electronics DIAView has an authentication bypass vulnerability.
E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in
A code execution security issue exists in the affected product. An attacker with physical access could abuse the mainten
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to byp
A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page conta
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started