A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that cou
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS command
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attac
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which ca
There is a missing authentication vulnerability in some Huawei smartphone.Successful exploitation of this vulnerability
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform p
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authen
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allow
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a runnin
An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the proc
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applicat
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does no
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authenti
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original f
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function t
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authe
Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because o
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary conne
This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cl
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough aut
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerabl
An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthent
An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated at
An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated at
An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthe
An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticate
An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticate
An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated
In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started