An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authenticatio
An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Health
Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive informa
When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process.
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create P
Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdow
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Ser
NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical functi
A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacke
A user with device administrative privileges can change existing SMTP server settings on the device, without having to r
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and Th
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerab
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Se
NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adj
D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjac
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This v
The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it
Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulne
Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability all
Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows ne
Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR.
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation
* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Alti
IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a
An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ
Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footag
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access
When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pre
Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow f
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the devic
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the Peop
Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENES
CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote
Microsoft Bluetooth Driver Spoofing Vulnerability
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web ap
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for
D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attac
A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guar
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started