An issue was discovered in Epikur before 20.1.1. A Glassfish 4.1 server with a default configuration is running on TCP p
Dell EMC PowerScale OneFS versions 8.2.0 - 9.1.0 contain a privilege escalation vulnerability. A non-admin user with eit
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to t
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download t
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in
Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to al
An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can
Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive devic
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before
On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic fai
On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authenticat
In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessi
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The curren
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to ca
Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vul
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Inf
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Passwor
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to s
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of t
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that ca
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requir
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the S
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API.
ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on versi
TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to del
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as report
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing se
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remot
Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not re
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sendi
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidat
tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code t
tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code t
A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows
There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical acce
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products th
ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due
A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote a
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),
Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vu
SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network, to access via HTTP to the int
Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In version
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyo
A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started