Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1095

1095 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-10906 Magnetism Studios Endurance NSXPC com.MagnetismStudios.endurance.helper loadModuleNamed:WithReply missing authentication — Endurance 8.4 High2025-09-24
CVE-2025-41716 Unauthenticated User Enumeration via Missing Authentication — Solution Builder 5.3 Medium2025-09-24
CVE-2025-41715 Missing Authentication for Database Access in Web Application — Device Sphere 9.8 Critical2025-09-24
CVE-2025-9983 Lack of Authentication for RTSP stream — G2 7.5AIHighAI2025-09-22
CVE-2025-10772 huggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authentication — LeRobot 6.3 Medium2025-09-21
CVE-2022-4980 General Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin Page — Crypto Application Server (CAS) 9.8 -2025-09-19
CVE-2025-34190 Vasion Print (formerly PrinterLogic) PrinterInstallerClientService Authentication Bypass via LD_PRELOAD Hooking — Print Application 6.7 -2025-09-19
CVE-2025-10672 whuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authentication — AIBattery 7.8 High2025-09-18
CVE-2025-59345 Dragonfly did not enable authentication for some Manager’s endpoints — dragonfly 9.1AICriticalAI2025-09-17
CVE-2025-9971 Planet Technology|Industrial Cellular Gateway - Missing Authentication — ICG-2510WG-LTE (EU/US) 9.8 Critical2025-09-17
CVE-2025-59358 Denial of Service via Unauthorized Access to Chaos Mesh debugging server 7.5 High2025-09-15
CVE-2025-10452 Gotac|Statistical Database System - Missing Authentication — Statistical Database System 9.8 Critical2025-09-15
CVE-2025-10204 Unauth Admin Reset Password on AC Smart II — AC Smart II 9.8 -2025-09-14
CVE-2025-58434 Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover — Flowise 9.8 Critical2025-09-12
CVE-2025-10267 NewType Infortech|NUP Portal - Missing Authentication — NUP Portal 5.3 Medium2025-09-12
CVE-2025-9214 Lenovo printers 安全漏洞 — LJ2206W Printer 5.4 Medium2025-09-11
CVE-2025-36757 Bypass of administrator login screen in SolaX Cloud — SolaX Cloud 9.8AICriticalAI2025-09-10
CVE-2025-7635 Calix GigaCenter ONT - Unauthenticated Telnet — GigaCenter ONT 9.8AICriticalAI2025-09-09
CVE-2025-7970 Rockwell Automation FactoryTalk Activation Manager Lack of Encryption Vulnerability — FactoryTalk Activation Manager 9.1AICriticalAI2025-09-09
CVE-2025-9160 Rockwell Automation CompactLogix® 5480 Code Execution Vulnerability — CompactLogix® 5480 6.8AIMediumAI2025-09-09
CVE-2025-42926 Missing Authentication check in SAP NetWeaver Application Server Java — SAP NetWeaver Application Server Java 5.3 Medium2025-09-09
CVE-2025-58443 FOG's authentication bypass leads to full SQL DB dump — fogproject 9.8AICriticalAI2025-09-06
CVE-2025-7045 Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action — Cloud SAML SSO – Single Sign On Login 6.5 Medium2025-09-06
CVE-2025-52551 Proprietary protocol allows for unauthenticated file operations — E2 Facility Management System 9.8AICriticalAI2025-09-02
CVE-2025-9815 alaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authentication — batteryKid 7.8 High2025-09-02
CVE-2025-58318 DIAView - Authentication Bypass Vulnerability — DIAView 9.8AICriticalAI2025-09-01
CVE-2025-7405 Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in MELSEC iQ-F Series CPU module — MELSEC iQ-F Series FX5U-32MT/ES 7.3 High2025-09-01
CVE-2025-54942 SUNNET Corporate Training Management System - Missing Authentication for Critical Function — Corporate Training Management System 9.8 -2025-08-30
CVE-2025-8861 Changing|TSA - Missing Authentication — TSA 9.8 Critical2025-08-29
CVE-2023-7308 SecGate3600 Firewall Information Disclosure via authManageSet.cgi — SecGate3600 Firewall 7.5AIHighAI2025-08-27

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1095 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.