CWE-1188— Insecure Default Initialization of Resource
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.— MITRE CWE catalog
362 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 7 of 8
- CVE-2025-38523MEDIUMCVSS 5.5EG 5.52025-08-16
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix the smbd_response slab to allow usercopy The handling of received data in the smbdirect client code involves using copy_to_iter() to copy data from the smbd_re…
- CVE-2022-49099MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix initialization of device object in vmbus_device_register() Initialize the device's dma_{mask,parms} pointers and the device's dma_mask value befo…
- CVE-2021-47343MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: dm btree remove: assign new_root only when removal succeeds remove_raw() in dm_btree_remove() may fail due to IO read error (e.g. read the content of origin block fails …
- CVE-2023-4194MEDIUMCVSS 5.5EG 5.52023-08-07
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomple…
- CVE-2022-20466MEDIUMCVSS 5.5EG 5.52022-12-13
In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no ad…
- CVE-2020-0019MEDIUMCVSS 5.5EG 5.52020-12-14
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A…
- CVE-2020-0386MEDIUMCVSS 5.5EG 5.52020-09-17
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User executi…
- CVE-2019-2197MEDIUMCVSS 5.5EG 5.52019-11-13
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privil…
- CVE-2022-36349MEDIUMCVSS 5.2EG 5.52022-11-11
Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-5591MEDIUMCVSS 5.4EG 5.42026-01-05
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
- CVE-2025-52622MEDIUMCVSS 5.4EG 5.42025-12-02
The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mi…
- CVE-2025-43797MEDIUMCVSS 5.4EG 5.42025-09-15
In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is �…
- CVE-2025-27809MEDIUMCVSS 5.4EG 5.42025-03-25
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
- CVE-2024-45313MEDIUMCVSS 5.4EG 5.42024-09-02
Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the configuration for LaTeX compiles was insecure by defa…
- CVE-2022-47196MEDIUMCVSS 5.4EG 5.42023-01-19
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escala…
- CVE-2022-47194MEDIUMCVSS 5.4EG 5.42023-01-19
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escala…
- CVE-2026-100260MEDIUMCVSS 5.3EG 5.32026-09-30
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
- CVE-2026-93338MEDIUMCVSS 5.3EG 5.32026-09-18
Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with t…
- CVE-2026-54907MEDIUMCVSS 5.3EG 5.32026-09-17
Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthen…
- CVE-2026-49462MEDIUMCVSS 5.3EG 5.32026-09-11
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default…
- CVE-2026-62416MEDIUMCVSS 5.3EG 5.32026-08-03
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, a…
- CVE-2026-41931MEDIUMCVSS 5.3EG 5.32026-05-06
Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can acces…
- CVE-2026-32046MEDIUMCVSS 5.3EG 5.32026-03-21
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leve…
- CVE-2026-32305MEDIUMCVSS 5.3EG 5.32026-03-20
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When…
- CVE-2026-1675MEDIUMCVSS 5.3EG 5.32026-02-07
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and including, 2.3.1 due to the use of a predictable default value for the secret bypass key created during installation without…
- CVE-2025-53602MEDIUMCVSS 5.3EG 5.32025-07-04
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.
- CVE-2024-41975MEDIUMCVSS 5.3EG 5.32025-03-18
An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.
- CVE-2024-5801MEDIUMCVSS 5.3EG 5.32024-08-12
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filterin…
- CVE-2024-26267MEDIUMCVSS 5.3EG 5.32024-02-20
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.head…
- CVE-2024-22207MEDIUMCVSS 5.3EG 5.32024-01-15
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served …
- CVE-2023-33949MEDIUMCVSS 5.3EG 5.32023-05-24
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addre…
- CVE-2023-28978MEDIUMCVSS 5.3EG 5.32023-04-17
An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information. In the default configuration it is possible to re…
- CVE-2022-42467MEDIUMCVSS 5.3EG 5.32022-10-19
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the developer to explici…
- CVE-2019-19251MEDIUMCVSS 5.3EG 5.32019-12-10
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made …
- CVE-2017-5491MEDIUMCVSS 5.3EG 5.32017-01-15
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
- CVE-2026-78013MEDIUMCVSS 5.2EG 5.22026-10-09
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with local access could potentially exploit this vu…
- CVE-2026-33921MEDIUMCVSS 5.2EG 5.22026-08-11
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without…
- CVE-2025-41245MEDIUMCVSS 4.9EG 4.92025-09-29
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.
- CVE-2026-54800MEDIUMCVSS 4.8EG 4.82026-07-09
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA secu…
- CVE-2025-64781MEDIUMCVSS 4.7EG 4.72025-12-12
In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to "Do not limit" in the initial configuration. With this configura…
- CVE-2020-16873MEDIUMCVSS 4.7EG 4.72020-09-11
<p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target sys…
- CVE-2025-2441MEDIUMCVSS 4.6EG 4.62025-04-09
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does no…
- CVE-2021-33130MEDIUMCVSS 4.6EG 4.62022-05-12
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2025-59044MEDIUMCVSS 4.4EG 4.42025-09-09
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when himmelblau.conf `id_attr_map = name` (the default configuration). B…
- CVE-2024-44096MEDIUMCVSS 4.4EG 4.42024-09-13
there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2020-12327MEDIUMCVSS 4.4EG 4.42020-11-12
Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2026-76276MEDIUMCVSS 4.3EG 4.32026-10-07
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splun…
- CVE-2026-20265MEDIUMCVSS 4.3EG 4.32026-06-17
In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which coul…
- CVE-2026-46430MEDIUMCVSS 4.3EG 4.32026-05-20
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows…
- CVE-2025-62802MEDIUMCVSS 4.3EG 4.32025-10-28
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential …
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →