The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a
A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows re
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows re
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit i
Locally installed application can bypass the permission check and perform system operations that require permission.
Windows Update Stack Elevation of Privilege Vulnerability
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authenticatio
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common S
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19
Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, whic
A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the prog
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solution
An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may b
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by u
Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulne
Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability a
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to exe
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentica
D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remo
Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerabil
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthen
Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint S
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a u
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unautho
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information v
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020
Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive inform
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive informat
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process
An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information vi
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware updat
LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware upda
An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive informati
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that ar
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started