Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-306

MITRE ↗

CWE-306

1,075
CRITICAL
1,154
HIGH
604
MEDIUM
41
LOW
3,053 CVEs · Page 8/62
9.4
CVE-2026-22552

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat

9.4
CVE-2026-26051

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat

9.4
CVE-2026-26288

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat

9.4
CVE-2026-25192

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat

9.4
CVE-2026-29796

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat

9.4
CVE-2026-3893

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to direct

9.4
CVE-2026-42569

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS a

9.4
CVE-2026-44592

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the N

9.4
CVE-2026-49973

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot

9.4
CVE-2026-40702

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res

9.4
CVE-2026-16242

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was

9.4
CVE-2026-61186

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The

9.4
CVE-2026-61203

Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The suppor

9.4
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 t

9.4
CVE-2026-44100

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di

9.4
CVE-2026-50516

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el

9.4
CVE-2026-73296

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobi

9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnera

9.3
CVE-2026-28766

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

9.3
CVE-2026-46912

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Sup

9.3
CVE-2026-55450

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can

9.3
CVE-2026-59706

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f

9.3
CVE-2026-48325

ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary co

9.3
CVE-2026-61175

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica

9.3
CVE-2026-59506

: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (develop

9.3
CVE-2026-71566

FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end

9.1
CVE-2026-21445

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple cr

9.1
CVE-2025-68715

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor

9.1
CVE-2026-25137

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odo

9.1
CVE-2026-1632

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication,

9.1
CVE-2026-2234

C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to rea

9.1
CVE-2026-25848

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

9.1
CVE-2025-70146

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera

9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 1

9.1
CVE-2026-33340

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side

9.1
CVE-2026-34758

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to N

9.1
CVE-2026-32211

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information

9.1
CVE-2026-34952

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connect

9.1
CVE-2026-40289

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow

9.1
CVE-2026-34279

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana

9.1
CVE-2026-34285

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp

9.1
CVE-2026-34286

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp

9.1
CVE-2026-27843

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be

9.1
CVE-2026-41473

CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints

9.1
CVE-2026-36356

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica

9.1
CVE-2026-22924

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly

9.1
CVE-2026-31242

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via

9.1
CVE-2026-31071

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated

9.1
CVE-2026-8602

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at

Frequently Asked Questions

What is CWE-306?

CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-306?

There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.

How can I protect against CWE-306 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.

Detect CWE-306 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.

Get Started