Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1097

1097 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-22279 OmniCore RobotWare Missing Authentication Vulnerability — RobotWare 9.8 Critical2021-12-13
CVE-2021-42783 Missing Authentication in debug_post_set.cgi in D-Link DWR-932C E1 Firmware 1.0.0.4 — DWR-932C E1 9.8 -2021-11-23
CVE-2021-39233 Container-related datanode operations can be called without authorization — Apache Ozone 7.5 -2021-11-19
CVE-2021-41266 Authentication bypass issue in the Operator Console — console 8.6 High2021-11-15
CVE-2021-42539 Emerson WirelessHART Gateway — WirelessHART Gateway 8.0 High2021-10-22
CVE-2021-27395 Siemens Simatic Process Historian 访问控制错误漏洞 — SIMATIC Process Historian 2013 and earlier 8.1 -2021-10-12
CVE-2021-3825 Missing Authorization Checks in LiderAhenk — Lider 9.6 Critical2021-10-01
CVE-2021-41104 web_server allows OTA update without checking user defined basic auth username & password — esphome 7.5 High2021-09-28
CVE-2019-10941 SINEMA Server 访问控制错误漏洞 — SINEMA Server 5.3 -2021-09-14
CVE-2021-33543 UDP Technology/Geutebrück camera devices: Authentication Bypass — E2 Series 9.8 Critical2021-09-13
CVE-2021-32800 Bypass of Two Factor Authentication in Nextcloud server — security-advisories 8.1 High2021-09-07
CVE-2021-31868 Rapid7 Nexpose Security Console Ticket Access Authentication Vulnerability — Nexpose 4.3 Medium2021-08-19
CVE-2021-37697 Sensitive information leak in Welcome of tmerc-cogs — tmerc-cogs 7.1 High2021-08-11
CVE-2021-37696 Sensitive information leak in MassDM of tmerc-cogs — tmerc-cogs 7.1 High2021-08-11
CVE-2020-7389 Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environment — X3 5.5 Medium2021-07-22
CVE-2021-22772 Schneider Electric Easergy T200产品访问控制错误漏洞 — Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 ((IEC104) SC2-04IEC-07000100 and earlier), and Easergy T200 ((DNP3) SC2-04DNP-07000102 and earlier) 9.8 -2021-07-21
CVE-2021-22784 Schneider Electric C-Bus Toolkit 访问控制错误漏洞 — C-Bus Toolkit v1.15.8 and prior 9.8 -2021-07-21
CVE-2021-31337 Siemens SINAMICS SL150 访问控制错误漏洞 — SINAMICS Medium Voltage Products 9.8 -2021-06-28
CVE-2021-32709 Creation of order credits was not validated by acl in admin orders — platform 4.9 Medium2021-06-24
CVE-2021-32700 Supply chain attack via MiTM against users — ballerina-lang 9.1 Critical2021-06-22
CVE-2021-32659 Automatic room upgrade handling can be used maliciously to bridge a room non-consentually — matrix-appservice-bridge 6.5 Medium2021-06-16
CVE-2021-32930 Advantech Iview 访问控制错误漏洞 — iView 9.8 -2021-06-11
CVE-2020-25697 X.Org X Server 访问控制错误漏洞 — xorg-x11-server 7.0 -2021-05-26
CVE-2021-32453 SITEL CAP/PRX information exposure — CAP/PRX 6.5 Medium2021-05-17
CVE-2021-20998 WAGO: Managed Switches: Unauthorized creation of user accounts — 0852-0303 10.0 Critical2021-05-13
CVE-2021-1499 Cisco HyperFlex HX Data Platform File Upload Vulnerability — Cisco HyperFlex HX Data Platform 5.3 Medium2021-05-06
CVE-2021-21535 Dell Hybrid Client 访问控制错误漏洞 — Dell Hybrid Client (DHC) 7.4 High2021-04-30
CVE-2021-29442 Authentication bypass — nacos 8.6 High2021-04-27
CVE-2021-20990 Fibaro Home Center Unauthenticated access to shutdown, reboot and reboot to recovery mode — Fibaro Home Center 7.5 High2021-04-19
CVE-2020-27225 Eclipse Platform 访问控制错误漏洞 — Eclipse Platform 7.8 -2021-03-09

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1097 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.