NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotel
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and ch
An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted P
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This cou
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 24
AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP h
Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafte
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A
Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the d
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.
Windows Mobile Device Management Elevation of Privilege Vulnerability
Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.
Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera)
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on t
The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address),
The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any serv
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missi
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missi
Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attack
Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a leg
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechan
In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can at
A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Gr
Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lac
Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0.
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privil
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allo
Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. Th
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI fl
Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories with
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read,
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can re
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started