Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related
GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format an
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the De
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes runn
Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration val
A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe
Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify th
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauth
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to ve
An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, all
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 befo
In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Q
An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A
In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. T
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-p
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser all
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bol
ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstat
An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Pan
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download docu
An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock scr
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to
An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Blu
An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and th
Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Da
A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area
A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22)
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from a
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configu
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authe
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stac
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer ove
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive info
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th
It was found that default configuration of Heketi does not require any authentication potentially exposing the managemen
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfac
The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribu
Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Ca
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started