Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1096

1096 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-32041 OpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth Bootstrap — OpenClaw 6.9 Medium2026-03-19
CVE-2025-71257 BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass — FootPrints 7.3 High2026-03-19
CVE-2026-24062 Insufficient XPC Client validation leading to local privilege escalation in Arturia Software Center — Software Center 7.3 -2026-03-18
CVE-2026-22174 OpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP Probe — OpenClaw 6.8 Medium2026-03-18
CVE-2026-2603 Keycloak: keycloak: unauthorized authentication via disabled saml identity provider — Red Hat build of Keycloak 26.2 8.1 High2026-03-18
CVE-2026-22727 Cloud Foundry unprotected internal endpoints — Cloud Foundry 7.5 High2026-03-17
CVE-2026-1264 IBM Sterling B2B Integrator and IBM Sterling File Gateway Improper Access Controls — Sterling B2B Integrator 7.1 High2026-03-17
CVE-2026-3207 TIBCO BPM Enterprise Remote Code Execution (RCE) Vulnerability — TIBCO BPM Enterprise 9.8AICriticalAI2026-03-17
CVE-2026-32297 Angeet ES3 KVM unauthenticated arbitrary file write — ES3 KVM 7.5 High2026-03-17
CVE-2026-32296 Sipeed NanoKVM unauthenticated Wi-Fi configuration endpoint — NanoKVM 8.2 High2026-03-17
CVE-2026-32291 GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console — Comet KVM 6.8 Medium2026-03-17
CVE-2026-4312 DrangSoft|GCB/FCB Audit Software - Missing Authentication — GCB/FCB Audit Software 9.8 Critical2026-03-17
CVE-2017-20222 Telesquare SKT LTE Router SDT-CS3B1 Unauthenticated Remote Reboot — SDT-CS3B1 7.5 High2026-03-16
CVE-2026-4187 Tiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authentication — Easy7 Integrated Management Platform 5.3 Medium2026-03-15
CVE-2017-20220 Serviio PRO 1.8 Unauthenticated Password Change via REST API — Serviio PRO 7.5 High2026-03-15
CVE-2017-20217 Serviio PRO 1.8 REST API Information Disclosure — Serviio PRO 7.5 High2026-03-15
CVE-2026-2491 Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability — DIRIS A-40 8.8AIHighAI2026-03-13
CVE-2026-3558 Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability — Hue Bridge 8.8AIHighAI2026-03-13
CVE-2026-32594 Parse Server GraphQL WebSocket endpoint bypasses security middleware — parse-server 9.1AICriticalAI2026-03-13
CVE-2026-31944 LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect link — LibreChat 7.6 High2026-03-13
CVE-2026-31882 Dagu SSE Authentication Bypass in Basic Auth Mode — dagu 7.5 High2026-03-13
CVE-2025-13779 Configuration Data Spill — AWIN GW100 rev.2 8.3 High2026-03-13
CVE-2025-13778 Device Reboot Control — AWIN GW100 rev.2 6.5 Medium2026-03-13
CVE-2025-15515 Vivo EasyShare 安全漏洞 — Easyshare 4.7 -2026-03-13
CVE-2026-22192 Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage — SNMP Web Pro 9.9 Critical2026-03-13
CVE-2026-3611 Honeywell IQ4x BMS Controller Missing authentication for critical function — IQ4E 10.0 Critical2026-03-12
CVE-2026-32231 ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data — zeptoclaw 8.2 High2026-03-12
CVE-2026-31881 Runtipi unauthenticated /api/auth/reset-password allows operator account takeover during active reset window — runtipi 7.7 High2026-03-11
CVE-2019-25483 Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k Restricted Shell Escape — AR-5310 8.4 High2026-03-11
CVE-2026-23662 Azure IoT Explorer Information Disclosure Vulnerability — Azure IoT Explorer 7.5 High2026-03-10

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1096 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.