Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1096

1096 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-31963 HCL BigFix IVR is impacted by improper authentication and missing CSRF protection — BigFix IVR 2.9 Low2026-01-07
CVE-2026-0650 OpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path Normalization — Flagr 8.2 -2026-01-07
CVE-2026-0625 D-Link DSL/DIR/DNS Command Injection via DNS Configuration Endpoint — DSL-2640B 9.8 -2026-01-05
CVE-2025-14346 WHILL Model C2和WHILL Model F 访问控制错误漏洞 — Model C2 Electric Wheelchair 9.8 Critical2026-01-05
CVE-2025-15026 Unauthenticated configuration import allows administrative account creation using AWIE component — Infra Monitoring 9.8 Critical2026-01-05
CVE-2025-3646 Petlibro Smart Pet Feeder Platform through 1.7.31 Authorization Bypass via Device Share API — Smart Pet Feeder Platform 7.3 High2026-01-03
CVE-2026-21446 Bagisto Missing Authentication on Installer API Endpoints — bagisto 9.8 -2026-01-02
CVE-2026-21445 Langflow Missing Authentication on Critical API Endpoints — langflow 9.4 -2026-01-02
CVE-2020-36904 Selea CarPlateServer 4.0.1.6 Remote Program Execution via Configuration Endpoint — Selea CarPlateServer (CPS) 7.5 High2025-12-31
CVE-2024-58336 Akuvox Smart Intercom S539 Unauthenticated Video Stream Disclosure — Akuvox Smart Doorphone 5.3 Medium2025-12-30
CVE-2022-50790 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure — Impact/Pulse/First 7.5 High2025-12-30
CVE-2025-66377 Pexip Infinity 访问控制错误漏洞 — Infinity 7.5 High2025-12-25
CVE-2025-3232 Mitsubishi Electric Europe smartRTU Missing Authentication for Critical Function — smartRTU 7.5 High2025-12-24
CVE-2019-25248 Beward N100 M2.1.6 Unauthenticated RTSP Video Stream Disclosure — N100 H.264 VGA IP Camera 7.5 High2025-12-24
CVE-2019-25240 Rifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticated Live Stream Disclosure via animate.cgi — DVR 9.8 Critical2025-12-24
CVE-2019-25236 iSeeQ Hybrid DVR WH-H4 1.03R Unauthenticated Live Stream Disclosure — Hybrid DVR WH-H4 9.8 Critical2025-12-24
CVE-2018-25140 FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated Websocket Device Manipulation — Thermal Traffic Cameras 7.5 High2025-12-24
CVE-2018-25141 FLIR Thermal Traffic Cameras V1.01-0bb5b27 Unauthenticated RTSP Stream Disclosure — FLIR Thermal Traffic Cameras 7.5 High2025-12-24
CVE-2018-25139 FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosure — FLIR AX8 Thermal Camera 7.5 High2025-12-24
CVE-2018-25136 FLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated RTSP Stream Disclosure — Brickstream 3D+ 7.5 High2025-12-24
CVE-2018-25137 FLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated Config File Disclosure — FLIR Brickstream 3D+ 7.5 High2025-12-24
CVE-2018-25134 Synaccess netBooter NP-02x/NP-08x 6.8 Authentication Bypass via webNewAcct.cgi — netBooter NP-02x/NP-08x 9.8 Critical2025-12-24
CVE-2025-66445 Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer — Hitachi Infrastructure Analytics Advisor 7.1 High2025-12-24
CVE-2023-53964 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability — Impact/Pulse/First 9.8 Critical2025-12-22
CVE-2023-53974 D-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated Request — DSL-124 Wireless N300 ADSL2+ 7.5 High2025-12-22
CVE-2023-53969 Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password Change — Screen SFT DAB 600/C 7.5 High2025-12-22
CVE-2023-53970 Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board Config — Screen SFT DAB 600/C 7.5 High2025-12-22
CVE-2023-53967 Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password Change — Screen SFT DAB 600/C 7.5 High2025-12-22
CVE-2023-53968 Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase Account — Screen SFT DAB 600/C 9.8 Critical2025-12-22
CVE-2025-12049 Sharp Media Player MP-01 安全漏洞 — Media Player MP-01 9.1AICriticalAI2025-12-22

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1096 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.