Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 37/62
8.1
CVE-2024-7781

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7

8.1
CVE-2024-9861

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up

8.1
CVE-2024-40405

Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a

8.1
CVE-2024-41967

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of

8.1
CVE-2024-5718

Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows re

8.1
CVE-2024-5721

Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows re

8.1
CVE-2024-42455

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit i

7.9
CVE-2021-26280

Locally installed application can bypass the permission check and perform system operations that require permission.

7.8
CVE-2024-26235

Windows Update Stack Elevation of Privilege Vulnerability

7.8
CVE-2024-2860

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authenticatio

7.8
CVE-2024-7125

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common S

7.8
CVE-2024-8012

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19

7.8
CVE-2022-25770

Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, whic

7.8
CVE-2022-23862

A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696

7.8
CVE-2024-47574

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4

7.7
CVE-2023-6221

The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the prog

7.6
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solution

7.6
CVE-2022-32503

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may b

7.5
CVE-2023-40393

An authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS

7.5
CVE-2023-6942

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5

7.5
CVE-2023-49115

MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by u

7.5
CVE-2022-48621

Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulne

7.5
CVE-2023-51571

Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability a

7.5
CVE-2023-4857

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to exe

7.5
CVE-2024-21006

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

7.5
CVE-2024-21007

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

7.5
CVE-2024-1491

The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentica

7.5
CVE-2023-44413

D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remo

7.5
CVE-2023-51587

Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerabil

7.5
CVE-2024-27942

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthen

7.5
CVE-2024-1662

Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint S

7.5
CVE-2024-37368

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a u

7.5
CVE-2024-31916

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unautho

7.5
CVE-2024-37767

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information v

7.5
CVE-2024-21183

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

7.5
CVE-2024-35124

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020

7.5
CVE-2024-45049

Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without

7.5
CVE-2024-8751

A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface

7.5
CVE-2024-48768

An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive inform

7.5
CVE-2024-48771

An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive informat

7.5
CVE-2024-48773

An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process

7.5
CVE-2024-48774

An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information vi

7.5
CVE-2024-48775

An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the

7.5
CVE-2024-48776

An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware updat

7.5
CVE-2024-48777

LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware upda

7.5
CVE-2024-48791

An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive informati

7.5
CVE-2024-45276

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

7.5
CVE-2024-5749

Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

7.5
CVE-2024-21272

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that ar

7.5
CVE-2024-48950

An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started