The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rog
Windows LSA Spoofing Vulnerability
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-au
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a mal
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functiona
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root acc
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several pr
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote att
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
Lexmark products through 2022-02-10 have Incorrect Access Control.
A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software
An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Sof
An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Softwar
An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Softw
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without author
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization th
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS
Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Reme
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIM
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attac
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According t
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability
Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.
An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring syste
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily
On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to c
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitiv
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported
Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an
Free5gc v3.2.1 is vulnerable to Information disclosure.
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprun
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started