Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 35/62
9.8
CVE-2024-3701

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows

9.8
CVE-2024-21014

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony E

9.8
CVE-2023-51478

Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Bu

9.8
CVE-2023-39457

Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers

9.8
CVE-2023-42121

Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers

9.8
CVE-2024-32735

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8

9.8
CVE-2024-0949

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability

9.8
CVE-2024-6422

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

9.8
CVE-2024-5910 KEV

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account

9.8
CVE-2024-38437

D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

9.8
CVE-2024-7007

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an

9.8
CVE-2024-7503

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ

9.8
CVE-2024-42462

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i

9.8
CVE-2024-36445

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

9.8
CVE-2024-4428

Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Ma

9.8
CVE-2024-8584

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to

9.8
CVE-2024-7015

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authent

9.8
CVE-2024-8277

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,

9.8
CVE-2024-6981

OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without pro

9.8
CVE-2024-8310

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full

9.8
CVE-2024-8456

Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, a

9.8
CVE-2024-46293

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authori

9.8
CVE-2024-9289

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version

9.8
CVE-2024-8943

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi

9.8
CVE-2024-9984

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re

9.8
CVE-2024-45274

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

9.8
CVE-2024-49328

Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns al

9.8
CVE-2024-49604

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registrati

9.8
CVE-2024-47575 KEV

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2

9.8
CVE-2024-10386

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a

9.8
CVE-2024-50477

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile

9.8
CVE-2024-50486

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo

9.8
CVE-2024-50487

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe

9.8
CVE-2024-50489

Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo

9.8
CVE-2024-10284

The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This

9.8
CVE-2024-40404

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp

9.8
CVE-2024-10924

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass

9.8
CVE-2024-0012 KEV

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access t

9.8
CVE-2024-21855

A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP re

9.8
CVE-2024-38643

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited,

9.8
CVE-2024-47138

The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when

9.8
CVE-2024-11680 KEV

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated at

9.8
CVE-2024-50375

A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by

9.8
CVE-2024-54983

An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.

9.8
CVE-2024-54984

An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this

9.6
CVE-2024-22212

Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users t

9.6
CVE-2024-23618

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can

9.6
CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prio

9.6
CVE-2024-40087

Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP ser

9.4
CVE-2024-9137

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started