Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authe
The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WI
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It
A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vu
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the m
ironic-image is a container image to run OpenStack Ironic as part of Metal³. Prior to version capm3-v1.4.3, if Ironic is
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authenti
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows re
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this
In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This i
An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentica
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authenticat
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to t
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does
An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by c
Microsoft Defender Security Feature Bypass Vulnerability
SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRN
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file mi
mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in versi
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized action
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It
Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be i
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker t
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A
Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web ser
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Contr
The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited
Microsoft SharePoint Server Security Feature Bypass Vulnerability
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active sessio
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks f
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities t
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php
Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which m
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to
The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, with
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauth
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth
A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthe
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures)
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started