A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-esc
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adj
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without aut
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/document
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemo
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin
ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that al
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Su
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to ex
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au
rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service d
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis
Ebyte device web management interface does not consistently enforce authentication before granting access to administra
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating un
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentic
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lac
Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) expos
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gate
This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho
A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started