Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1097

1097 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-0257 HCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other services — HCL DevOps Deploy / HCL Launch 6.3 Medium2025-04-02
CVE-2025-25060 Hammock AssetView 访问控制错误漏洞 — AssetView 9.8 -2025-04-02
CVE-2024-56469 IBM UrbanCode Deploy (UCD) / IBM DevOps Deploy missing authentication — UrbanCode Deploy 6.3 Medium2025-03-27
CVE-2024-45356 Xiaomi phone framework has unauthorized access vulnerability — Xiaomi phone framework has unauthorized access vulnerability 7.3 High2025-03-27
CVE-2024-45355 Xiaomi phone framework has unauthorized access vulnerability — Xiaomi phone framework 5.5 Medium2025-03-27
CVE-2024-45483 Missing GRUB password in B&R APROL — APROL 6.1AIMediumAI2025-03-25
CVE-2025-0256 HCL DevOps Deploy / HCL Launch is susceptible to a sensitive information disclosure — HCL DevOps Deploy / HCL Launch 4.3 Medium2025-03-24
CVE-2025-25068 Bypassing MFA Enforcement on Plugin Endpoints — Mattermost 7.5 High2025-03-21
CVE-2024-8196 Missing Authentication for Critical Function in mintplex-labs/anything-llm — mintplex-labs/anything-llm 9.1 -2025-03-20
CVE-2024-12869 Improper Authentication in infiniflow/ragflow — infiniflow/ragflow 3.5 -2025-03-20
CVE-2024-8053 Improper Authentication in open-webui/open-webui — open-webui/open-webui 9.1 -2025-03-20
CVE-2024-8057 Improper Access Control in danswer-ai/danswer — danswer-ai/danswer 9.8 -2025-03-20
CVE-2024-6842 Exposure of Sensitive Information in mintplex-labs/anything-llm — mintplex-labs/anything-llm 7.5 -2025-03-20
CVE-2024-9919 Missing Authentication Check in parisneo/lollms-webui — parisneo/lollms-webui 7.5 -2025-03-20
CVE-2024-50630 Synology Drive Server 访问控制错误漏洞 — Synology Drive Server 7.5 High2025-03-19
CVE-2024-23943 MB connect line: Cloud API access due to a lack of authentication for a critical function — mbCONNECT24 9.1 Critical2025-03-18
CVE-2025-2344 IROAD Dash Cam X5/Dash Cam X6 API Endpoint missing authentication — Dash Cam X5 5.3 Medium2025-03-16
CVE-2024-52285 Siemens SiPass Integrated 访问控制错误漏洞 — SiPass integrated AC5102 (ACC-G2) 5.3 Medium2025-03-11
CVE-2025-23194 Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component) — SAP NetWeaver Enterprise Portal (OBN component) 5.3 Medium2025-03-11
CVE-2025-27256 GE Vernova EnerVista UR 访问控制错误漏洞 — EnerVista UR Setup 8.3 High2025-03-10
CVE-2025-24924 GMOD Apollo Missing Authentication for Critical Function — Apollo 9.8 Critical2025-03-05
CVE-2025-21355 Microsoft Bing Remote Code Execution Vulnerability — Microsoft Bing 8.6 High2025-02-19
CVE-2025-25224 LuxSoft LuxCal Web Calendar 访问控制错误漏洞 — The LuxCal Web Calendar 7.5 -2025-02-18
CVE-2025-24865 mySCADA myPRO Manager Missing Authentication for Critical Function — myPRO Manager 10.0 Critical2025-02-13
CVE-2025-0896 Orthanc Server Missing Authentication for Critical Function — Orthanc server 9.8 Critical2025-02-13
CVE-2025-0108 PAN-OS: Authentication Bypass in the Management Web Interface — Cloud NGFW 9.8 -2025-02-12
CVE-2025-26366 Q-Free MAXTIME Suite 访问控制错误漏洞 — MaxTime 7.5 High2025-02-12
CVE-2025-26365 Q-Free MAXTIME Suite 访问控制错误漏洞 — MaxTime 7.5 High2025-02-12
CVE-2025-26364 Q-Free MAXTIME Suite 访问控制错误漏洞 — MaxTime 7.5 High2025-02-12
CVE-2025-26363 Q-Free MAXTIME Suite 访问控制错误漏洞 — MaxTime 7.5 High2025-02-12

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1097 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.