Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-12-29 CVE-2020-10148 Missing Authentication for Critical Function vulnerability in Solarwinds Orion Platform 2019.4/2020.2/2020.2.1
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands.
network
low complexity
solarwinds CWE-306
critical
9.8
2020-12-29 CVE-2020-9208 Missing Authentication for Critical Function vulnerability in Huawei Imanager Neteco 6000 V600R021C00
There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00.
network
low complexity
huawei CWE-306
6.5
2020-12-23 CVE-2020-29551 Missing Authentication for Critical Function vulnerability in Urve 24.03.2020
An issue was discovered in URVE Build 24.03.2020.
network
low complexity
urve CWE-306
critical
9.1
2020-12-22 CVE-2020-24580 Missing Authentication for Critical Function vulnerability in Dlink Dsl2888A Firmware
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55.
high complexity
dlink CWE-306
7.5
2020-12-17 CVE-2020-35197 Missing Authentication for Critical Function vulnerability in Docker Memcached Docker Image
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-17 CVE-2020-35196 Missing Authentication for Critical Function vulnerability in Docker Rabbitmq Docker Image 3.7.12
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-17 CVE-2020-35195 Missing Authentication for Critical Function vulnerability in Docker Haproxy Docker Image
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-17 CVE-2020-35192 Missing Authentication for Critical Function vulnerability in Hashicorp Vault
The official vault docker images before 0.11.6 contain a blank password for a root user.
network
low complexity
hashicorp CWE-306
critical
9.8
2020-12-17 CVE-2020-35191 Missing Authentication for Critical Function vulnerability in Drupal Docker Images 8.3.0Fpmalpine/8.3.1Fpmalpine/8.5.10Fpmalpine
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
drupal CWE-306
critical
9.8
2020-12-17 CVE-2020-35190 Missing Authentication for Critical Function vulnerability in Plone
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
plone CWE-306
critical
9.8