Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,699 CVEs tagged with CWE-3061,020 Critical, 1,018 High, 612 Medium, 49 Low, 0 Unrated.

CVE-2020-35187

Published Dec 17, 2020

The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35185

Published Dec 17, 2020

The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected vers…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25621

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. Th…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35469

Published Dec 16, 2020

The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS contain…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35468

Published Dec 16, 2020

The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35193

Published Dec 16, 2020

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected ver…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35467

Published Dec 15, 2020

The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35466

Published Dec 15, 2020

The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35464

Published Dec 15, 2020

Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may al…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35463

Published Dec 15, 2020

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container ma…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35462

Published Dec 15, 2020

Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a r…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-16102

Published Dec 14, 2020

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29311

Published Dec 10, 2020

Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the so…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26829

Published Dec 9, 2020

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication che…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-27902

Published Dec 8, 2020

An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able t…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28946

Published Dec 8, 2020

An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain the configuration file, inclu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28937

Published Dec 3, 2020

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29389

Published Dec 2, 2020

The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the D…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27985

Published Nov 23, 2020

Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and ex…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,176-2,200 of 2,699 CVEsPage 88 of 108