Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-12-16 CVE-2020-25621 Missing Authentication for Critical Function vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
local
low complexity
solarwinds CWE-306
8.4
2020-12-16 CVE-2020-35469 Missing Authentication for Critical Function vulnerability in Softwareag Terracotta Server OSS 5.4.1
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.
network
low complexity
softwareag CWE-306
critical
9.8
2020-12-16 CVE-2020-35468 Missing Authentication for Critical Function vulnerability in Appbase Streams 2.1.2
The Appbase streams Docker image 2.1.2 contains a blank password for the root user.
network
low complexity
appbase CWE-306
critical
9.8
2020-12-16 CVE-2020-35193 Missing Authentication for Critical Function vulnerability in Sonarsource Sonarqube Docker Image
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
sonarsource CWE-306
critical
9.8
2020-12-15 CVE-2020-35467 Missing Authentication for Critical Function vulnerability in Docker Docs 20201214
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-15 CVE-2020-35466 Missing Authentication for Critical Function vulnerability in Blackfire Docker Image 20201214
The Blackfire Docker image through 2020-12-14 contains a blank password for the root user.
network
low complexity
blackfire CWE-306
critical
9.8
2020-12-15 CVE-2020-35464 Missing Authentication for Critical Function vulnerability in Weave Cloud Agent 1.3.0
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.
network
low complexity
weave CWE-306
critical
9.8
2020-12-15 CVE-2020-35463 Missing Authentication for Critical Function vulnerability in Instana Dynamic APM 1.0.0
Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user.
network
low complexity
instana CWE-306
critical
9.8
2020-12-15 CVE-2020-35462 Missing Authentication for Critical Function vulnerability in Coscale Agent Project Coscale Agent 3.16.0
Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user.
network
low complexity
coscale-agent-project CWE-306
critical
9.8
2020-12-14 CVE-2020-16102 Missing Authentication for Critical Function vulnerability in Gallagher Command Centre
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart.
network
low complexity
gallagher CWE-306
8.2