Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and mod
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated at
The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with I
An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the i
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (ak
An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or era
PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constr
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulner
Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provi
An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a cr
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 ver
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctl
A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A spec
Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vul
NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to b
D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjac
D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability a
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to es
The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group me
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attac
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from
The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905.
Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authenti
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication
Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Pr
Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escala
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code exe
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a me
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet
An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network proto
Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documen
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netr
Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in
The product exposes a service that is intended for local only to all network interfaces without any authentication.
Missing Authentication - User & System Configuration
Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Gar
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint
A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.2
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an att
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific e
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts). Supported ver
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started