Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1096

1096 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-48391 JetBrains YouTrack 访问控制错误漏洞 — YouTrack 7.7 High2025-05-20
CVE-2025-32738 I-O Data HDL-T 访问控制错误漏洞 — HDL-TC1 5.3 Medium2025-05-15
CVE-2025-0132 Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services — Cortex XDR Broker VM 5.3AIMediumAI2025-05-14
CVE-2024-23815 Siemens Desigo CC 访问控制错误漏洞 — Desigo CC 7.5 High2025-05-13
CVE-2024-46506 NetAlertX 安全漏洞 — NetAlertX 10.0 Critical2025-05-13
CVE-2025-4560 Netvision ISOinsight - Missing Authentication — ISOinsight 6.5 Medium2025-05-12
CVE-2025-4557 ZONG YU Parking Management System - Missing Authentication — Parking Management System 9.1 Critical2025-05-12
CVE-2025-4555 ZONG YU Okcat Parking Management Platform - Missing Authentication — Okcat Parking Management Platform 9.8 Critical2025-05-12
CVE-2025-4382 Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm 5.9 Medium2025-05-09
CVE-2025-3759 Missing Authentication for Changing Device Configuration in WF2220 — WF2220 9.8AICriticalAI2025-05-08
CVE-2025-3758 Exposure of Device Configuration without Authentication in WF2220 — WF2220 7.5AIHighAI2025-05-08
CVE-2025-20210 Cisco Catalyst Center Unprotected API Endpoint — Cisco Digital Network Architecture Center (DNA Center) 7.3 High2025-05-07
CVE-2025-4268 TOTOLINK A720R cstecgi.cgi missing authentication — A720R 5.3 Medium2025-05-05
CVE-2025-1495 IBM Business Automation Workflow missing authentication — IBM Business Automation Workflow 4.3 Medium2025-05-03
CVE-2025-4019 20120630 Novel-Plus GeneratorController.java genCode missing authentication — Novel-Plus 7.3 High2025-04-28
CVE-2025-4018 20120630 Novel-Plus CrawlController.java addCrawlSource missing authentication — Novel-Plus 5.3 Medium2025-04-28
CVE-2025-4015 20120630 Novel-Plus SessionController.java list missing authentication — Novel-Plus 5.3 Medium2025-04-28
CVE-2025-46275 Planet Technology Network Products Missing Authentication for Critical Function — WGS-804HPT-V2 9.8 Critical2025-04-24
CVE-2025-32377 Rasa Pro Missing Authentication For Voice Connector APIs — rasa-pro-security-advisories 6.5 Medium2025-04-18
CVE-2025-32433 Erlang/OTP SSH Vulnerable to Pre-Authentication RCE — otp 10.0 Critical2025-04-16
CVE-2025-27538 MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users — Mattermost 2.2 Low2025-04-16
CVE-2025-30215 NATS-Server Fails to Authorize Certain Jetstream Admin APIs — nats-server 9.6 Critical2025-04-15
CVE-2025-32782 Ash Authentication email link auto-click account confirmation vulnerability — ash_authentication 5.3 Medium2025-04-15
CVE-2025-2567 Lantronix Xport Missing Authentication for Critical Function — Xport 9.8 Critical2025-04-15
CVE-2025-3474 Panels - Critical - Access bypass - SA-CONTRIB-2025-033 — Panels 9.1AICriticalAI2025-04-09
CVE-2025-29870 Inaba Denki Sangyo Wi-Fi AP UNIT 访问控制错误漏洞 — AC-WPS-11ac 7.5 High2025-04-09
CVE-2024-41793 Siemens SENTRON 7KT PAC1260 Data Manager 访问控制错误漏洞 — SENTRON 7KT PAC1260 Data Manager 8.6 High2025-04-08
CVE-2024-41791 Siemens SENTRON 7KT PAC1260 Data Manager 访问控制错误漏洞 — SENTRON 7KT PAC1260 Data Manager 7.3 High2025-04-08
CVE-2025-3248 Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code — langflow 9.8 Critical2025-04-07
CVE-2025-0257 HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other services — HCL DevOps Deploy / HCL Launch 6.3 Medium2025-04-02

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1096 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.