CWE-306— Missing Authentication for Critical Function
2,153 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-306page 11 of 44
- CVE-2020-3448MEDIUMCVSS 5.8EG 5.82020-08-17
A vulnerability in an access control mechanism of Cisco Cyber Vision Center Software could allow an unauthenticated, remote attacker to bypass authentication and access internal services that are running on an affected device. The vulnerab…
- CVE-2020-3461MEDIUMCVSS 5.3EG 5.32020-07-31
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missi…
- CVE-2020-35184CRITICALCVSS 9.8EG 9.82020-12-17
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with…
- CVE-2020-35185CRITICALCVSS 9.8EG 9.82020-12-17
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achi…
- CVE-2020-35186CRITICALCVSS 9.8EG 9.82020-12-17
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root acces…
- CVE-2020-35187CRITICALCVSS 9.8EG 9.82020-12-17
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System using the telegraf docker container deployed by affected versions of the docker image may allow a remote attacker to…
- CVE-2020-35189CRITICALCVSS 9.8EG 9.82020-12-17
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve…
- CVE-2020-35190CRITICALCVSS 9.8EG 9.82020-12-17
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attac…
- CVE-2020-35191CRITICALCVSS 9.8EG 9.82020-12-17
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker t…
- CVE-2020-35192CRITICALCVSS 9.8EG 9.82020-12-17
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a bl…
- CVE-2020-35193CRITICALCVSS 9.8EG 9.82020-12-16
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to ach…
- CVE-2020-35195CRITICALCVSS 9.8EG 9.82020-12-17
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docker image may allow a remote attacker to …
- CVE-2020-35196CRITICALCVSS 9.8EG 9.82020-12-17
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a…
- CVE-2020-35197CRITICALCVSS 9.8EG 9.82020-12-17
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker…
- CVE-2020-35226HIGHCVSS 7.1EG 7.12021-03-10
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.
- CVE-2020-3531CRITICALCVSS 9.8EG 9.82020-11-18
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does no…
- CVE-2020-35462CRITICALCVSS 9.8EG 9.82020-12-15
Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a remote attacker to achieve root access with a blank password.
- CVE-2020-35463CRITICALCVSS 9.8EG 9.82020-12-15
Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blan…
- CVE-2020-35464CRITICALCVSS 9.8EG 9.82020-12-15
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank pa…
- CVE-2020-35466CRITICALCVSS 9.8EG 9.82020-12-15
The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password.
- CVE-2020-35467CRITICALCVSS 9.8EG 9.82020-12-15
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password.
- CVE-2020-35468CRITICALCVSS 9.8EG 9.82020-12-16
The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password.
- CVE-2020-35469CRITICALCVSS 9.8EG 9.82020-12-16
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve root access with a…
- CVE-2020-35755HIGHCVSS 7.5EG 7.52021-05-03
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for which Read_ is prep…
- CVE-2020-35756HIGHCVSS 7.5EG 7.52021-05-03
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to return the device c…
- CVE-2020-35757CRITICALCVSS 9.8EG 9.82021-05-03
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default, but can be enabled b…
- CVE-2020-35758CRITICALCVSS 9.8EG 9.82021-05-03
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page …
- CVE-2020-35951CRITICALCVSS 9.9EG 9.92021-01-01
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall w…
- CVE-2020-3598MEDIUMCVSS 6.5EG 6.52020-10-08
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to access confidential information or make configuration changes. The vulnerability is due to mi…
- CVE-2020-36125HIGHCVSS 7.1EG 7.12021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint direc…
- CVE-2020-36239CRITICALCVSS 9.8EG 9.82021-07-29
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version…
- CVE-2020-36245HIGHCVSS 8.8EG 8.82021-02-17
GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent. The attacker must be able to reach TCP port 7912, e.g., by being on the same Wi-Fi network.
- CVE-2020-36333CRITICALCVSS 9.1EG 9.12021-05-05
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
- CVE-2020-36713CRITICALCVSS 9.8EG 9.82023-06-07
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthent…
- CVE-2020-36724CRITICALCVSS 9.8EG 9.82023-06-07
The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use of a loose compari…
- CVE-2020-36871HIGHCVSS 8.7EG 0.02025-11-26
ESCAM QD-900 WIFI HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint allows remote download of a compressed configuration backup without requiring authe…
- CVE-2020-36873HIGHCVSS 8.7EG 0.02025-11-26
Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed configurati…
- CVE-2020-36874HIGHCVSS 8.7EG 0.02025-11-26
ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed configuration backup without requiring…
- CVE-2020-36892CRITICALCVSS 9.8EG 9.82025-12-10
Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate…
- CVE-2020-36894HIGHCVSS 7.5EG 7.52025-12-10
Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects t…
- CVE-2020-36904HIGHCVSS 7.5EG 7.52025-12-31
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication th…
- CVE-2020-36963HIGHCVSS 7.5EG 7.52026-01-28
Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/Downlo…
- CVE-2020-37146HIGHCVSS 7.5EG 7.52026-02-07
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET req…
- CVE-2020-37157HIGHCVSS 7.5EG 7.52026-02-07
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration…
- CVE-2020-3920HIGHCVSS 8.1EG 8.12020-03-27
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.
- CVE-2020-3952CRITICALCVSS 9.8EG 9.8⚠ KEV2020-04-10
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.
- CVE-2020-3977MEDIUMCVSS 6.5EG 6.52020-09-22
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypa…
- CVE-2020-4471MEDIUMCVSS 6.5EG 6.52020-06-15
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726.
- CVE-2020-4670CRITICALCVSS 9.1EG 9.12021-05-17
IBM Planning Analytics Local 2.0 connects to a Redis server. The Redis server, an in-memory data structure store, running on the remote host is not protected by password authentication. A remote attacker can exploit this to gain unauthoriz…
- CVE-2020-4958CRITICALCVSS 9.8EG 9.82021-01-21
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.
Map vulnerabilities like CWE-306 to your infrastructure
EchelonGraph correlates every CVE — across CWE-306 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →