There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request
Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure S
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo
Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attac
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: POS). Sup
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects).
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticate
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP serv
SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switc
Enel X JuiceBox 40 Telnet Service Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows
Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software
The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r
Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server co
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported ver
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing p
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started