← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tangro
1Business Workflow
Jun 17, 2026
Dec 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required.
1Docker
1Memcached Docker Image
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allo...Show more
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Docker
1Rabbitmq Docker Image
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docke...Show more
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Docker
1Haproxy Docker Image
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a...Show more
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Hashicorp
1Vault
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve ro...Show more
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Drupal
1Drupal Docker Images
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow...Show more
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Plone
1Plone
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may a...Show more
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Docker
1Adminer
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to...Show more
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Docker
1Composer Docker Image
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achie...Show more
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Kong
1Kong Alpine Docker Image
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote...Show more
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Influxdata
1Telegraf
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a...Show more
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Docker
1Ghost Alpine Docker Image
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remo...Show more
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Epson
1Eps Tse Server 8 Firmware
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?d...Show more
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.Show less
1Solarwinds
1N Central
Jun 17, 2026
Dec 16, 2020
N/A· v4
8.4 HIGH· v3
2.1 LOW· v2
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.
1Softwareag
1Terracotta Server Oss
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve...Show more
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve root access with a blank password.Show less
1Appbase
1Streams
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank passwo...Show more
The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password.Show less
1Sonarsource
1Sonarqube Docker Image
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a rem...Show more
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Show less
1Docker
1Docs
Jun 17, 2026
Dec 15, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a...Show more
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password.Show less
1Blackfire
1Blackfire Docker Image
Jun 17, 2026
Dec 15, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a bla...Show more
The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password.Show less
1Weave
1Cloud Agent
Jun 17, 2026
Dec 15, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root acc...Show more
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.Show less