Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,942 CVEs tagged with CWE-3061,105 Critical, 1,150 High, 635 Medium, 52 Low, 0 Unrated.

CVE-2020-27285

Published Jan 6, 2021

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35951

Published Jan 1, 2021

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectiv…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-10148

Published Dec 29, 2020

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
60.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-9208

Published Dec 29, 2020

There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access to the module can exploit thi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29551

Published Dec 23, 2020

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts ar…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24580

Published Dec 22, 2020

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP addre…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26173

Published Dec 18, 2020

An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-35197

Published Dec 17, 2020

The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35196

Published Dec 17, 2020

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container d…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35195

Published Dec 17, 2020

The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35192

Published Dec 17, 2020

The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35191

Published Dec 17, 2020

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affecte…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35190

Published Dec 17, 2020

The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by af…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35186

Published Dec 17, 2020

The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the do…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35184

Published Dec 17, 2020

The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35189

Published Dec 17, 2020

The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected version…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35187

Published Dec 17, 2020

The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35185

Published Dec 17, 2020

The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected vers…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25621

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. Th…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35469

Published Dec 16, 2020

The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS contain…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35468

Published Dec 16, 2020

The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35193

Published Dec 16, 2020

The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected ver…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,401-2,425 of 2,942 CVEsPage 97 of 118