IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missi
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did no
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerabili
The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for cour
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured as
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settin
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to
OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to acce
An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network ac
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication f
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to int
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthentic
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges t
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between t
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to cr
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by ma
An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART int
HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, with
The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, a
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the gr
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV r
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept s
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in
A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenti
There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authenticat
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi
Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot In
The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-c
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi"
In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl
A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, rem
An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app c
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attac
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulner
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid usernam
DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emu
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Contr
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutat
A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attac
IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality al
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file name
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started