Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using aff
Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed usin
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using
The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affect
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affe
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System us
The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected vers
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed u
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated at
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. Syst
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System u
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer doc
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the admin
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root u
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. S
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker c
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. Syst
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password fo
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. Sy
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API com
Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Versi
The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote at
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different end
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead t
openSIS through 7.4 has Incorrect Access Control.
Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remot
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the se
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore sh
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown t
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind cred
CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Da
A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-on
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users m
A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALA
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center
SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some s
Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetad
UltraLog Express device management interface does not properly perform access authentication in some specific pages/func
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pai
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for conne
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform priv
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started