Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the Writ
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affec
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP
The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The us
An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticat
An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthent
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect
Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 messag
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Man
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the
A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected
Password recovery vulnerability in SICK SIM2x00 (ARM) Partnumber 1092673 and 1081902 with firmware version < 1.2.0 allow
Password recovery vulnerability in SICK SIM1012 Partnumber 1098146 with firmware version <2.2.0 allows an unprivileged r
A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to uplo
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does n
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security
The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allow
In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead
The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function
The software does not perform any authentication for critical system functionality.
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay net
A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collectio
Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this
Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sa
A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and c
In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sens
Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock t
Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the passwor
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can c
The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously,
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An a
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page l
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote at
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing una
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX acti
A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected dev
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started