Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1091

1091 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-34160 Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services — chamilo-lms 8.6 High2026-04-14
CVE-2026-33715 Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action — chamilo-lms 7.2 High2026-04-14
CVE-2026-26159 Remote Desktop Licensing Service Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2026-04-14
CVE-2026-26160 Remote Desktop Licensing Service Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2026-04-14
CVE-2025-53847 Fortinet FortiOS 访问控制错误漏洞 — FortiOS 6.2 Medium2026-04-14
CVE-2026-40289 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions — PraisonAI 9.1 Critical2026-04-14
CVE-2026-4810 Remote Code Execution in Google Agent Development Kit (ADK) — Agent Development Kit (ADK) 9.8 -2026-04-13
CVE-2026-6129 zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication — chatgpt-on-wechat CowAgent 7.3 High2026-04-12
CVE-2026-6126 zhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication — chatgpt-on-wechat CowAgent 7.3 High2026-04-12
CVE-2026-5724 Missing Authentication on Streaming gRPC Replication Endpoint — temporal 5.9 -2026-04-10
CVE-2026-40184 Unauthenticated Access to Uploaded Files in TREK — TREK 3.7 Low2026-04-10
CVE-2026-5777 Security Misconfiguration Vulnerability in Atom 3x Projector — Atom 3X Projector 8.8 -2026-04-10
CVE-2026-39848 Dockyard's Unauthenticated Cron Endpoint in Dockyard Enables Container Enumeration and Database Manipulation — dockyard 6.5 Medium2026-04-09
CVE-2026-33788 Junos OS Evolved: Local, authenticated attacker can gain privileged access to FPCs — Junos OS Evolved 7.8 High2026-04-09
CVE-2026-4436 GPL Odorizers GPL750 Missing Authentication for Critical Function — GPL750 (XL4) 8.6 High2026-04-09
CVE-2026-39987 marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass — marimo 9.8AICriticalAI2026-04-09
CVE-2025-30650 Junos OS: Privileged local user can gain access to a Linux-based FPC as root — Junos OS 6.7 Medium2026-04-08
CVE-2026-39393 Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms — ci4ms 8.1 High2026-04-08
CVE-2026-5300 Missing Authentication for Critical Function in coolercontrold — coolercontrold 5.9 Medium2026-04-08
CVE-2026-35584 FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration — freescout 8.2AIHighAI2026-04-07
CVE-2026-35523 Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocol — strawberry 7.5 High2026-04-07
CVE-2026-22679 Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint — E-cology 9.8 Critical2026-04-07
CVE-2026-35450 WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php — AVideo 5.3 Medium2026-04-06
CVE-2026-5676 Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication — A8000R 7.3 High2026-04-06
CVE-2026-5632 assafelovic gpt-researcher HTTP REST API Endpoint missing authentication — gpt-researcher 7.3 High2026-04-06
CVE-2026-5616 JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication — JeecgBoot 7.3 High2026-04-06
CVE-2026-4272 CVE-2026-4272 - Bluetooth Remote Execution of System Commands Vulnerability — Barcode Scanners 8.1 High2026-04-05
CVE-2019-25686 Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service — Core FTP 7.5 High2026-04-05
CVE-2019-25678 C4G BLIS 3.4 SQL Injection via users_select.php — Basic Laboratory Information System 8.2 High2026-04-05
CVE-2018-25246 Wikipedia 12.0 Denial of Service via Search — Wikipedia 7.5 High2026-04-04

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1091 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.