The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony E
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Bu
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers
Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers
An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.
Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Ma
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to
Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authent
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,
OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without pro
OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, a
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authori
The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version
The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns al
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registrati
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe
Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access t
A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP re
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited,
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated at
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this
Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users t
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prio
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP ser
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started