A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauth
Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff inform
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allow
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, iOS 17.1
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache
There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can pote
The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. SCP and SFTP plugins
A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (A
jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs coul
Cloud hypervisor is a Virtual Machine Monitor for Cloud workloads. This vulnerability allows users to close arbitrary op
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python
The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manag
The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in vers
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up t
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipel
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not inc
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The at
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain com
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, ad
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker w
Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of thi
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does n
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' acces
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary c
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary c
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary c
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA100
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Aut
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows fo
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started