Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 53/62
9.8
CVE-2020-35462

Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using aff

9.8
CVE-2020-35463

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed usin

9.8
CVE-2020-35464

Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using

9.8
CVE-2020-35466

The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affect

9.8
CVE-2020-35467

The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affe

9.8
CVE-2020-35193

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System us

9.8
CVE-2020-35468

The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected vers

9.8
CVE-2020-35469

The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed u

9.8
CVE-2020-28929

Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated at

9.8
CVE-2020-35185

The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System

9.8
CVE-2020-35187

The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. Syst

9.8
CVE-2020-35189

The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System u

9.8
CVE-2020-35184

The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer doc

9.8
CVE-2020-35186

The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the admin

9.8
CVE-2020-35190

The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root u

9.8
CVE-2020-35191

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. S

9.8
CVE-2020-35192

The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker c

9.8
CVE-2020-35195

The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. Syst

9.8
CVE-2020-35196

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password fo

9.8
CVE-2020-35197

The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. Sy

9.8
CVE-2020-10148 KEV

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com

9.4
CVE-2020-10265

Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Versi

9.4
CVE-2020-25747

The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote at

9.1
CVE-2020-7048

The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any

9.1
CVE-2020-9278

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by

9.1
CVE-2019-19104

The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different end

9.1
CVE-2020-7589

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead t

9.1
CVE-2020-13382

openSIS through 7.4 has Incorrect Access Control.

9.1
CVE-2020-16167

Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remot

9.1
CVE-2020-6294

Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any

9.1
CVE-2020-12506

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the se

9.1
CVE-2020-15243

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore sh

9.1
CVE-2020-29551

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown t

8.8
CVE-2020-9330

Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind cred

8.8
CVE-2020-10264

CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Da

8.8
CVE-2020-9004

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-on

8.8
CVE-2020-5589

SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X

8.8
CVE-2020-24363 KEV

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP

8.8
CVE-2018-11764

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users m

8.6
CVE-2019-13933

A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALA

8.6
CVE-2020-6964

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center

8.6
CVE-2020-6235

SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities

8.4
CVE-2020-25621

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security

8.2
CVE-2020-12505

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some s

8.1
CVE-2020-10965

Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetad

8.1
CVE-2020-3920

UltraLog Express device management interface does not properly perform access authentication in some specific pages/func

8.1
CVE-2020-11539

An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pai

8.1
CVE-2020-5870

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for conne

8.1
CVE-2020-26649

AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php

7.8
CVE-2020-7954

An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform priv

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started