Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options im
A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not require
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cau
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can g
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mech
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servl
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users
Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this informa
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When uti
openstack-utils openstack-db has insecure password creation
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network acces
The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-l
A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Ro
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath bi
An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because B
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were sear
An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Laye
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, in
An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthentic
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou
A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4. An encrypted vo
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CP
An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests t
An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, librar
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restrict
Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40,
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unaut
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an una
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthe
IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due t
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthent
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all c
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that do
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights a
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an un
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started