The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authenticati
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, thi
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when access
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-0700010
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the use
In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by dire
In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in PO
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticate
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to v
Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configurati
Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows a
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a
A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and mod
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effe
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauth
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API.
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to exec
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getC
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote un
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, runnin
Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.
Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view a
In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authori
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS au
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set p
GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected
Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage pro
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous u
A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installat
Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two F
An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle atta
A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Histor
A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to
The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to acco
Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started