Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported v
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the docume
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this v
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this v
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the
TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without kno
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerabil
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows at
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when ac
In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the
Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may
Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 104
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.
The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerabi
The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthentic
ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 202
Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensiti
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnera
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnera
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to down
The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to chan
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported vers
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devi
Broadcom RAID Controller Web server (nginx) is serving private files without any authentication
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the manage
Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. A
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vul
Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier a
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modific
Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extractio
Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext
Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext
Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier all
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows e
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 an
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started