Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-306 (关键功能的认证机制缺失) — Vulnerability Class 1092

1092 vulnerabilities classified as CWE-306 (关键功能的认证机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-22207 OpenViking Missing root_api_key Allows Anonymous ROOT Access — OpenViking 9.8 Critical2026-02-26
CVE-2026-27509 Unitree Go2 Missing DDS Authentication Enables Adjacent RCE — Unitree Go2 8.0 High2026-02-26
CVE-2026-3194 Chia Blockchain RPC Server Master Passphrase get_private_key missing authentication — Blockchain 4.5 Medium2026-02-25
CVE-2026-27846 Missing authentication in Linksys MR9600, Linksys MX4200 — MR9600 4.6AIMediumAI2026-02-25
CVE-2026-2624 Authentication Bypass in ePati's Antikor NGFW — Antikor Next Generation Firewall (NGFW) 9.8 Critical2026-02-25
CVE-2026-27595 Parse Dashboard has incomplete authentication on AI Agent endpoint — parse-dashboard 9.1AICriticalAI2026-02-25
CVE-2026-26340 Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Stream Disclosure — Smart+ 7.5 -2026-02-24
CVE-2026-27584 ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints — actual 7.5 -2026-02-24
CVE-2025-14577 PHP Function Injection in Slican NPC/IPL/IPM/IPU — NCP 9.8AICriticalAI2026-02-24
CVE-2026-3053 DataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authentication — dinky 7.3 High2026-02-24
CVE-2026-23693 ElementsKit Elementor Addons < 3.7.9 Unauthenticated Mailchimp REST Endpoint — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor 10.0 Critical2026-02-23
CVE-2026-24790 Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller Missing Authentication for Critical Function — OdorEyes EcoSystem Pulse Bypass System with XL4 Controller 8.2 High2026-02-20
CVE-2026-26048 Jinan USR IOT Technology Limited (PUSR) USR-W610 Missing Authentication for Critical Function — USR-W610 7.5 High2026-02-20
CVE-2025-30410 Acronis Cyber Protect 访问控制错误漏洞 — Acronis Cyber Protect Cloud Agent 9.1AICriticalAI2026-02-20
CVE-2026-26319 OpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated Requests — openclaw 7.5 High2026-02-19
CVE-2025-14294 Razorpay for WooCommerce <= 4.7.8 - Missing Authentication to Unauthenticated Order Modification — Razorpay for WooCommerce 5.3 Medium2026-02-19
CVE-2026-27182 Saturn Remote Mouse Server UDP Command Injection RCE — Saturn Remote Mouse Server 8.4 High2026-02-18
CVE-2026-1670 Honeywell CCTV Products Missing Authentication for Critical Function — I-HIB2PI-UL 2MP IP 9.8 Critical2026-02-17
CVE-2025-7706 Improper Access Control in TUBITAK BILGEM's Liderahenk — Liderahenk 6.1 Medium2026-02-17
CVE-2026-2577 Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge — nanobot 10.0 Critical2026-02-16
CVE-2025-32063 Enabling SSH server on Infotainment ECU — Infotainment system ECU 6.8 Medium2026-02-15
CVE-2025-6792 One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message Interception — One to one user Chat by WPGuppy 5.3 Medium2026-02-14
CVE-2026-26333 Calero VeraSMART < 2022 R1 .NET Remoting Arbitrary File Read Leading to ViewState RCE — VeraSMART 9.1AICriticalAI2026-02-13
CVE-2026-26190 Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise — milvus 9.8 Critical2026-02-13
CVE-2026-26055 Unauthenticated Admission Webhook Endpoints in Yoke ATC — yoke 7.5 High2026-02-12
CVE-2026-26235 JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication — JUNG Smart Visu Server 7.5 High2026-02-12
CVE-2026-1729 AdForest <= 6.0.12 - Authentication Bypass — AdForest 9.8 Critical2026-02-12
CVE-2026-24789 ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function — ZLAN5143D 9.8 Critical2026-02-11
CVE-2026-25084 ZLAN Information Technology ZLAN5143D Missing Authentication for Critical Function — ZLAN5143D 9.8 Critical2026-02-11
CVE-2026-2249 Unauthenticated Remote Command Execution via Web Console in METIS DFS — METIS DFS 9.8 Critical2026-02-11

Vulnerabilities classified as CWE-306 (关键功能的认证机制缺失) represent 1092 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.