Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Rabbitmq Docker Image CRITICAL 9.8
CVE-2020-35196

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using t…

Fix: after 3.7.12
Fix from $2,300 2020-12-17
Memcached Docker Image CRITICAL 9.8
CVE-2020-35197

The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached dock…

Fix: 1.5.11+
Fix from $2,300 2020-12-17
Composer Docker Image CRITICAL 9.8
CVE-2020-35184

The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by aff…

Fix: 1.8.3+
Fix from $2,300 2020-12-17
Adminer CRITICAL 9.8
CVE-2020-35186

The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed …

Fix: 4.7.0-fastcgi+
Fix from $2,300 2020-12-17
Ghost Alpine Docker Image CRITICAL 9.8
CVE-2020-35185

The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker conta…

Fix: 2.16.1+
Fix from $2,300 2020-12-17
Telegraf CRITICAL 9.8
CVE-2020-35187

The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker …

Fix: 1.9.4-alpine+
Fix from $2,300 2020-12-17
Kong Alpine Docker Image CRITICAL 9.8
CVE-2020-35189

The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker containe…

Fix: 1.0.2+
Fix from $2,300 2020-12-17
Eps Tse Server 8 Firmware CRITICAL 9.8
CVE-2020-28929

Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve a…

No fix yet
Fix from $2,300 2020-12-16
N Central HIGH 8.4
CVE-2020-25621

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to …

Mitigation only
Fix from $1,950 2020-12-16
Sonarqube Docker Image CRITICAL 9.8
CVE-2020-35193

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker cont…

Mitigation only
Fix from $2,300 2020-12-16
Streams CRITICAL 9.8
CVE-2020-35468

The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container…

Mitigation only
Fix from $2,300 2020-12-16
Terracotta Server Oss CRITICAL 9.8
CVE-2020-35469

The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the…

Mitigation only
Fix from $2,300 2020-12-16
Dynamic Apm CRITICAL 9.8
CVE-2020-35463

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the In…

Mitigation only
Fix from $2,300 2020-12-15
Cloud Agent CRITICAL 9.8
CVE-2020-35464

Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weav…

Mitigation only
Fix from $2,300 2020-12-15
Blackfire Docker Image CRITICAL 9.8
CVE-2020-35466

The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire …

Fix: after 2020-12-14
Fix from $2,300 2020-12-15
Docs CRITICAL 9.8
CVE-2020-35467

The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker D…

Fix: after 2020-12-14
Fix from $2,300 2020-12-15
Coscale Agent CRITICAL 9.8
CVE-2020-35462

Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale…

Mitigation only
Fix from $2,300 2020-12-15
Logo\! 8 Bm Firmware CRITICAL 9.8
CVE-2020-25228

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affecte…

Fix: 8.3+
Fix from $2,300 2020-12-14
Command Centre HIGH 8.2
CVE-2020-16102

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid confi…

Fix: 7.90.0 / 8.00.1252+
Fix from $1,950 2020-12-14
Modicon M340 Bmxp341000 Firmware CRITICAL 9.8
CVE-2020-7540

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Mod…

Fix: 3.3 / 3.30+
Fix from $2,300 2020-12-11
Ubilling CRITICAL 9.8
CVE-2020-29311EPSS 6%

Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being trigg…

No fix yet
Fix from $2,300 2020-12-10
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-26829

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…

Mitigation only
Fix from $2,300 2020-12-09
Ik 401 Firmware HIGH 7.5
CVE-2020-28946

An improper webserver configuration on Plum IK-401 devices with firmware before 1.02 allows an attacker (with network access to the device) to obtain…

Fix: 1.02+
Fix from $1,950 2020-12-08
Openclinic HIGH 7.5
CVE-2020-28937

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test…

No fix yet
Fix from $1,950 2020-12-03
Crux Linux Docker Image CRITICAL 9.8
CVE-2020-29389

The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed…

Fix: after 3.4
Fix from $2,300 2020-12-02
V1600d4l Firmware MEDIUM 5.5
CVE-2020-29379

An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update scri…

No fix yet
Fix from $1,600 2020-11-29
F\@st 3486 Router Firmware MEDIUM 5.3
CVE-2020-29138

Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated us…

Mitigation only
Fix from $1,600 2020-11-27
72408a Firmware CRITICAL 9.8
CVE-2020-29058

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…

No fix yet
Fix from $2,300 2020-11-24
Security Onion HIGH 7.8
CVE-2020-27985

Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the s…

Fix: 2.3.10+
Fix from $1,950 2020-11-23
Easergy T300 Firmware CRITICAL 9.8
CVE-2020-7561

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide ra…

Fix: after 2.7
Fix from $2,300 2020-11-19