Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1096

1096 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-43644 Improper authentication in the SOCKS5 inbound in sing-box — sing-box 9.1 Critical2023-09-25
CVE-2023-4516 Schneider Electric IGSS 访问控制错误漏洞 — IGSS Update Service (IGSSupdateservice.exe) 7.8 High2023-09-14
CVE-2023-41367 Missing Authentication check in SAP NetWeaver (Guided Procedures) — SAP NetWeaver (Guided Procedures) 5.3 Medium2023-09-12
CVE-2023-4815 Missing Authentication for Critical Function in answerdev/answer — answerdev/answer 6.5 -2023-09-07
CVE-2023-31132 Cacti Privilege Escalation — cacti 7.8 High2023-09-05
CVE-2023-39981 MXsecurity Device Information Disclosure — MXsecurity Series 7.5 High2023-09-02
CVE-2023-34392 Missing Authentication for Critical Function — SEL-5037 SEL Grid Configurator 8.2 High2023-08-31
CVE-2023-38030 Saho ADM100&ADM-100FP - Execute Code — ADM100 7.5 High2023-08-28
CVE-2023-38028 Saho ADM100&ADM-100FP - Broken Access Control — ADM100 9.1 Critical2023-08-28
CVE-2023-40585 Unauthenticated access to Ironic API — ironic-image 7.3 High2023-08-25
CVE-2023-38422 Walchem Intuition Missing Authentication for Critical Function — Intuition 9 7.5 High2023-08-23
CVE-2023-36846 Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files — Junos OS 5.3 Medium2023-08-17
CVE-2023-36847 Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files — Junos OS 5.3 Medium2023-08-17
CVE-2023-38186 Windows Mobile Device Management Elevation of Privilege Vulnerability — Windows Server 2022 8.8 High2023-08-08
CVE-2023-37373 Siemens RUGGEDCOM CROSSBOW 访问控制错误漏洞 — RUGGEDCOM CROSSBOW 5.3 Medium2023-08-08
CVE-2023-39436 Information Disclosure in SAP Supplier Relationship Management — SAP Supplier Relationship Management 5.8 Medium2023-08-08
CVE-2023-37483 Improper Access Control Vulnerabilities in SAP PowerDesigner — SAP PowerDesigner 9.8 Critical2023-08-08
CVE-2023-36926 Information disclosure vulnerability in SAP Host Agent — SAP Host Agent 3.7 Low2023-08-08
CVE-2023-34329 Authentication Bypass via HTTP Header Spoofing — MegaRAC_SPx12 8.4 High2023-07-18
CVE-2023-37265 Incorrect identification of source IP addresses in CasaOS — CasaOS-Gateway 9.8 Critical2023-07-17
CVE-2023-35874 Improper authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform — SAP NetWeaver AS ABAP and ABAP Platform 6.0 Medium2023-07-11
CVE-2023-35873 Missing Authentication check in SAP NetWeaver Process Integration (Runtime Workbench) — SAP NetWeaver Process Integration (Runtime Workbench) 6.5 Medium2023-07-11
CVE-2023-35872 Missing Authentication check in SAP NetWeaver Process Integration (Message Display Tool) — SAP NetWeaver Process Integration (Message Display Tool) 6.5 Medium2023-07-11
CVE-2023-2827 Missing Authentication in SAP Plant Connectivity and Production Connector for SAP Digital — SAP Plant Connectivity 7.9 High2023-06-13
CVE-2023-2187 Triangle MicroWorks SCADA Data Gateway 安全漏洞 — SCADA Data Gateway 5.3 Medium2023-06-07
CVE-2023-30604 Hitron Technologies Inc. CODA-5310 - Broken Access Control — Hitron CODA-5310 9.8 Critical2023-06-02
CVE-2023-25780 Status Internet Co.,Ltd. PowerBPM - Broken Access Control — PowerBPM 5.7 Medium2023-06-02
CVE-2022-4240 Unauthenticated API allowing an attacker to obtain the information about network resources — OneWireless 6.5 Medium2023-05-30
CVE-2023-1837 HYPR Server 访问控制错误漏洞 — HYPR Server 8.5 High2023-05-23
CVE-2023-32680 Missing SQL permissions check in metabase — metabase 5.8 Medium2023-05-18

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1096 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.