CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No further authentication is required. |
1Docker 1Memcached Docker Image Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allo...Show more |
1Docker 1Rabbitmq Docker Image Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docke...Show more |
1Docker 1Haproxy Docker Image Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a...Show more |
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve ro...Show more |
1Drupal 1Drupal Docker Images Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow...Show more |
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may a...Show more |
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to...Show more |
1Docker 1Composer Docker Image Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achie...Show more |
1Kong 1Kong Alpine Docker Image Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote...Show more |
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a...Show more |
1Docker 1Ghost Alpine Docker Image Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remo...Show more |
1Epson 1Eps Tse Server 8 Firmware Jun 17, 2026 Dec 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?d...Show more |
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords. |
1Softwareag 1Terracotta Server Oss Jun 17, 2026 Dec 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve...Show more |
The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank passwo...Show more |
1Sonarsource 1Sonarqube Docker Image Jun 17, 2026 Dec 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a rem...Show more |
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a...Show more |
1Blackfire 1Blackfire Docker Image Jun 17, 2026 Dec 15, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a bla...Show more |
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root acc...Show more |