Vulnerabilities > Missing Authentication for Critical Function

DATE CVE VULNERABILITY TITLE RISK
2020-12-17 CVE-2020-35186 Missing Authentication for Critical Function vulnerability in Docker Adminer
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-17 CVE-2020-35184 Missing Authentication for Critical Function vulnerability in Docker Composer Docker Image
The official composer docker images before 1.8.3 contain a blank password for a root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-17 CVE-2020-35189 Missing Authentication for Critical Function vulnerability in Kong Alpine Docker Image
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
kong CWE-306
critical
9.8
2020-12-17 CVE-2020-35187 Missing Authentication for Critical Function vulnerability in Influxdata Telegraf
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
influxdata CWE-306
critical
9.8
2020-12-17 CVE-2020-35185 Missing Authentication for Critical Function vulnerability in Docker Ghost Alpine Docker Image
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
docker CWE-306
critical
9.8
2020-12-16 CVE-2020-28929 Missing Authentication for Critical Function vulnerability in Epson EPS TSE Server 8 Firmware 21.0.11
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.
network
low complexity
epson CWE-306
critical
9.8
2020-12-16 CVE-2020-25621 Missing Authentication for Critical Function vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
local
low complexity
solarwinds CWE-306
8.4
2020-12-16 CVE-2020-35469 Missing Authentication for Critical Function vulnerability in Softwareag Terracotta Server OSS 5.4.1
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user.
network
low complexity
softwareag CWE-306
critical
9.8
2020-12-16 CVE-2020-35468 Missing Authentication for Critical Function vulnerability in Appbase Streams 2.1.2
The Appbase streams Docker image 2.1.2 contains a blank password for the root user.
network
low complexity
appbase CWE-306
critical
9.8
2020-12-16 CVE-2020-35193 Missing Authentication for Critical Function vulnerability in Sonarsource Sonarqube Docker Image
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user.
network
low complexity
sonarsource CWE-306
critical
9.8