A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated a
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a RES
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions pri
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the ex
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information a
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cis
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them
A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affect
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PH
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain t
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall ac
An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation So
Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the reco
Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local at
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected dev
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accesse
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypas
Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requ
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it i
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbit
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and una
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requi
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginIntercep
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotel
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a)
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain pr
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain pr
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4.
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an una
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative
Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. Th
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Che
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract s
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change
There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started