Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1097

1097 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8751 Vulnerability in SICK MSC800 — SICK MSC800 7.5 High2024-09-12
CVE-2024-8321 Ivanti EPM 安全漏洞 — Endpoint Manager 5.8 Medium2024-09-10
CVE-2024-8320 Ivanti EPM 安全漏洞 — Endpoint Manager 5.3 Medium2024-09-10
CVE-2024-7015 Improper Authentication in Profelis Informatics and Consulting's PassBOX — PassBox 9.8AICriticalAI2024-09-09
CVE-2024-8584 LEARNING DIGITAL Orca HCM - Missing Authentication — Orca HCM 9.8 Critical2024-09-09
CVE-2024-45075 IBM webMethods Integration privilege escalation — webMethods Integration 8.8 High2024-09-04
CVE-2024-4428 Sensetive Data Exposure in Menulux Managment Portal — Managment Portal 6.5AIMediumAI2024-08-29
CVE-2024-45049 Nix Hydra Missing authentication when triggering evaluations — hydra 7.5 High2024-08-27
CVE-2024-7940 Hitachi Energy MicroSCADA X SYS600 安全漏洞 — MicroSCADA SYS600 8.3 High2024-08-27
CVE-2024-43798 Chisel AUTH environment variable not respected in server entrypoint — chisel 8.6 High2024-08-26
CVE-2024-43272 WordPress Icegram Engage plugin <= 3.1.24 - Unauthenticated Unpublished Campaign Viewer vulnerability — Icegram 5.3 Medium2024-08-19
CVE-2024-42462 Bypass multifactor authentication — upKeeper Manager 9.8AICriticalAI2024-08-16
CVE-2024-38143 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability — Windows 11 Version 24H2 4.2 Medium2024-08-13
CVE-2024-3279 Improper Access Control in mintplex-labs/anything-llm — mintplex-labs/anything-llm 8.2AIHighAI2024-08-09
CVE-2024-35143 IBM Planning Analytics Local missing authentication — Planning Analytics Local 6.7 Medium2024-08-04
CVE-2024-7079 Openshift-console: unauthenticated installation of helm charts 6.5 Medium2024-07-24
CVE-2024-39601 Siemens CPCI85 Central Processing和SICORE Base system 访问控制错误漏洞 — CPCI85 Central Processing/Communication 6.5 Medium2024-07-22
CVE-2024-6895 Insecure Account Profile Management — YugabyteDB Anywhere 5.0 -2024-07-19
CVE-2024-5910 Expedition: Missing Authentication Leads to Admin Account Takeover — Expedition 9.8AICriticalAI2024-07-10
CVE-2024-6422 Pepperl+Fuchs: OIT Products can be manipulated via unintended Telnet access — OIT1500-F113-B12-CB 9.8 Critical2024-07-10
CVE-2024-1573 Mitsubishi Electric MC Works64 授权问题漏洞 — GENESIS64 5.9 Medium2024-07-04
CVE-2023-41918 Missing Authentication for Critical Function in Kiloview P1/P2 devices — P1/P2 10.0 Critical2024-07-02
CVE-2024-0949 Improper Access Control in Talya Informatics' Elektraweb — Elektraweb 9.8 Critical2024-06-27
CVE-2024-27169 Lack of authentication — Toshiba Tec e-Studio multi-function peripheral (MFP) 8.4 High2024-06-14
CVE-2024-5947 Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability — DSE855 6.5AIMediumAI2024-06-13
CVE-2024-5951 Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability — DSE855 6.5AIMediumAI2024-06-13
CVE-2024-5952 Deep Sea Electronics DSE855 Restart Missing Authentication Denial-of-Service Vulnerability — DSE855 6.5AIMediumAI2024-06-13
CVE-2024-32752 Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool — iSTAR Configuration Utility (ICU) 8.1AIHighAI2024-06-06
CVE-2024-22326 IBM System Storage improper authentication — System Storage DS8900F 5.0 Medium2024-06-06
CVE-2024-1662 Information Disclosure in Porty's PowerBank — PowerBank Application 7.5 High2024-06-05

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1097 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.