CWE-1188— Insecure Default Initialization of Resource
171 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 3 of 4
- CVE-2021-47343MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: dm btree remove: assign new_root only when removal succeeds remove_raw() in dm_btree_remove() may fail due to IO read error (e.g. read the content of origin block fails …
- CVE-2022-1278HIGHCVSS 7.5EG 7.52022-09-13
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
- CVE-2022-20342LOWCVSS 3.3EG 3.32022-08-12
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2022-20466MEDIUMCVSS 5.5EG 5.52022-12-13
In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no ad…
- CVE-2022-2196MEDIUMCVSS 5.8EG 8.82023-01-09
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…
- CVE-2022-24287HIGHCVSS 7.8EG 7.82022-05-20
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All version…
- CVE-2022-24706CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-26
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an instal…
- CVE-2022-25568HIGHCVSS 7.5EG 9.02022-03-24
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
- CVE-2022-31806CRITICALCVSS 9.8EG 9.82022-06-24
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the contr…
- CVE-2022-32480MEDIUMCVSS 4.3EG 6.52022-08-22
Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulne…
- CVE-2022-3262HIGHCVSS 8.1EG 8.12022-12-08
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confid…
- CVE-2022-36349MEDIUMCVSS 5.2EG 5.52022-11-11
Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-38745HIGHCVSS 7.8EG 7.82023-03-24
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
- CVE-2022-40468HIGHCVSS 7.5EG 7.52022-09-19
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.
- CVE-2022-41648CRITICALCVSS 9.8EG 9.82022-10-28
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may…
- CVE-2022-4224HIGHCVSS 8.8EG 8.82023-03-23
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
- CVE-2022-42467MEDIUMCVSS 5.3EG 5.32022-10-19
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the developer to explici…
- CVE-2022-46831MEDIUMCVSS 6.6EG 4.92022-12-08
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
- CVE-2022-47194MEDIUMCVSS 5.4EG 5.42023-01-19
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escala…
- CVE-2022-47196MEDIUMCVSS 5.4EG 5.42023-01-19
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escala…
- CVE-2022-48342MEDIUMCVSS 5.2EG 9.82023-02-23
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
- CVE-2022-48432MEDIUMCVSS 5.2EG 8.82023-03-29
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
- CVE-2022-48492HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2022-48493HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2023-1618HIGHCVSS 7.5EG 7.52023-05-19
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected modul…
- CVE-2023-27516HIGHCVSS 7.3EG 7.32023-10-12
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to…
- CVE-2023-27524HIGHCVSS 8.9EG 8.9⚠ KEV2023-04-24
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access…
- CVE-2023-28978MEDIUMCVSS 5.3EG 5.32023-04-17
An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information. In the default configuration it is possible to re…
- CVE-2023-31101MEDIUMCVSS 6.5EG 6.52023-05-22
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Use…
- CVE-2023-33949MEDIUMCVSS 5.3EG 5.32023-05-24
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addre…
- CVE-2023-3453HIGHCVSS 7.1EG 7.12023-08-23
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condit…
- CVE-2023-3485LOWCVSS 3.0EG 3.02023-06-30
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done…
- CVE-2023-35689HIGHCVSS 7.8EG 7.82023-08-14
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileg…
- CVE-2023-39169CRITICALCVSS 9.8EG 9.82023-12-07
The affected devices use publicly available default credentials with administrative privileges.
- CVE-2023-40708MEDIUMCVSS 5.8EG 5.82023-08-24
The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.
- CVE-2023-4194MEDIUMCVSS 5.5EG 5.52023-08-07
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomple…
- CVE-2023-45312HIGHCVSS 8.8EG 8.82023-10-10
In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.
- CVE-2023-48733MEDIUMCVSS 6.7EG 6.72024-02-14
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
- CVE-2023-5368MEDIUMCVSS 6.5EG 6.52023-10-04
On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes. This may permit a us…
- CVE-2023-6448CRITICALCVSS 9.8EG 9.8⚠ KEV2023-12-05
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
- CVE-2024-0001CRITICALCVSS 10.0EG 10.02024-09-23
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
- CVE-2024-0387MEDIUMCVSS 6.5EG 6.52024-02-26
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access con…
- CVE-2024-22207MEDIUMCVSS 5.3EG 5.32024-01-15
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served …
- CVE-2024-22388MEDIUMCVSS 5.9EG 5.92024-02-06
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
- CVE-2024-25610CRITICALCVSS 9.0EG 9.02024-02-20
In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog en…
- CVE-2024-25972HIGHCVSS 8.3EG 8.32024-03-01
Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a network-adjacent unauthenticated attacker to configure and control the affected product.
- CVE-2024-26267MEDIUMCVSS 5.3EG 5.32024-02-20
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.head…
- CVE-2024-28815CRITICALCVSS 9.8EG 9.82024-03-27
A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive information, changes to the system configuration, or execution of arbitrary commands within the cont…
- CVE-2024-2912CRITICALCVSS 10.0EG 10.02024-04-16
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the …
- CVE-2024-30124MEDIUMCVSS 4.0EG 4.02024-10-23
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →