Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 38/62
7.5
CVE-2024-48953

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authenticatio

7.5
CVE-2024-50589

An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Health

7.5
CVE-2024-53623

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive informa

7.4
CVE-2023-5935

When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process.

7.3
CVE-2024-22415

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +

7.3
CVE-2024-6635

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ

7.3
CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create P

7.3
CVE-2024-10774

Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web

7.2
CVE-2024-45844

BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdow

7.2
CVE-2024-47902

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir

7.1
CVE-2024-7516

A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle attackers to conduct remote Ser

6.8
CVE-2023-31033

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical functi

6.8
CVE-2024-20391

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacke

6.8
CVE-2024-5143

A user with device administrative privileges can change existing SMTP server settings on the device, without having to r

6.8
CVE-2024-7726

There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and

6.7
CVE-2023-25493

A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and Th

6.7
CVE-2024-35143

IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is

6.6
CVE-2024-22449

Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerab

6.6
CVE-2024-45229

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,

6.5
CVE-2022-38057

Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Se

6.5
CVE-2023-27357

NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adj

6.5
CVE-2023-41186

D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjac

6.5
CVE-2021-34983

NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This v

6.5
CVE-2024-1076

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it

6.5
CVE-2024-5947

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulne

6.5
CVE-2024-5951

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability all

6.5
CVE-2024-5952

Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows ne

6.5
CVE-2024-33622

Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR.

6.5
CVE-2024-39601

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste

6.5
CVE-2024-7079

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation

6.5
CVE-2024-6347

* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Alti

6.5
CVE-2024-35151

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a

6.5
CVE-2024-35294

An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ

6.5
CVE-2024-48442

Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2

6.5
CVE-2024-51362

The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footag

6.4
CVE-2024-48952

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access

6.4
CVE-2020-12484

When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pre

6.3
CVE-2024-39364

Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow f

6.3
CVE-2021-26278

The wifi module exposes the interface and has improper permission control, leaking sensitive information about the devic

5.9
CVE-2023-37495

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the Peop

5.9
CVE-2024-1573

Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENES

5.9
CVE-2024-8530

CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe

5.8
CVE-2024-8321

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote

5.7
CVE-2024-21306

Microsoft Bluetooth Driver Spoofing Vulnerability

5.5
CVE-2024-22513

djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web ap

5.5
CVE-2023-52949

Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for

5.4
CVE-2023-37325

D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attac

5.4
CVE-2024-41968

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

5.3
CVE-2023-51062

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0

5.3
CVE-2023-5253

A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guar

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started