CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
288 vulnerabilities with CWE-1188
CVE-2026-9262
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Initialization of a Resource with an Insecure Default
CVSS 6.5
CVE-2026-54359
HIGH
MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by default
CVE-2026-44892
HIGH
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVSS 7.5
CVE-2026-40994
HIGH
Spring Web Services - Wss4jSecurityInterceptor Disables WS-I BSP Validation by Default
CVSS 8.2
CVE-2026-46517
HIGH
LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVSS 7.8
CVE-2026-36616
MEDIUM
Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909 - Hardcoded WiFi Driver Credentials Exposure
CVSS 5.9
CVE-2026-36612
MEDIUM
Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Weak WPS Lockout Policy
CVSS 6.4
CVE-2026-44825
HIGH
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVSS 8.1
CVE-2026-9039
HIGH
Initialization of a resource with an insecure default in XCharge C6
CVE-2026-35672
HIGH
phpMyFAQ - Authentication Bypass via Empty API Token
CVSS 7.5
CVE-2026-24197
MEDIUM
Nvidia GeForce - Initialization of a Resource with an Insecure Default
CVSS 6.5
CVE-2026-46430
MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVSS 4.3
CVE-2026-45728
HIGH
Algernon: Single-file mode unconditionally enables debug mode
CVSS 7.5
CVE-2026-44670
CRITICAL
SiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuan
CVE-2026-44588
CRITICAL
SiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSS
CVE-2026-33376
HIGH
Grafana OSS Insecure Default IPv6 Allow-List Mask in Auth Proxy
CVSS 7.4
CVE-2026-43892
HIGH
AntSword: Incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection
CVSS 8.8
CVE-2026-30805
CRITICAL
Insecure Default Initialization in API Authentication leads to Authentication Bypass
CVSS 9.1
CVE-2026-6866
HIGH
Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel Server
CVE-2026-27662
HIGH
Siemens Simatic Hmi MTP1000 Unified Comfort Panel - Initialization of a Resource with an Insecure Default
CVSS 7.7
CVE-2026-41432
HIGH
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
CVSS 7.1
CVE-2026-44338
HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
CVE-2026-44109
CRITICAL
OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation
CVSS 9.8
CVE-2026-43581
CRITICAL
OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay Binding
CVSS 9.6
CVE-2026-41931
MEDIUM
Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handler
CVSS 5.3
Details
Vulnerabilities
288