CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
312 vulnerabilities with CWE-1188
CVE-2026-67208
CRITICAL
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVSS 9.8
CVE-2026-66066
CRITICAL
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
CVE-2026-65881
HIGH
Joomdle < 3.1.1 - Insecure Defaults Allow CMS Account Access
CVSS 7.5
CVE-2026-9680
MEDIUM
MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server
CVSS 5.8
CVE-2026-47668
CRITICAL
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVSS 10.0
CVE-2026-55708
LOW
Privacy/configuration issue when adding local data in views through 'unbound-control'
CVSS 3.1
CVE-2026-47393
CRITICAL
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVSS 9.8
CVE-2026-62415
CRITICAL
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2
CVSS 9.1
CVE-2026-60024
CRITICAL
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0
CVSS 9.8
CVE-2026-62185
HIGH
Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE
CVSS 7.6
CVE-2026-61439
HIGH
PraisonAI before 4.6.78 Prompt Injection Defense Bypass
CVSS 7.5
CVE-2026-54800
MEDIUM
Siemens CPCI85 Central Processing/Communication - Initialization of a Resource with an Insecure Default
CVSS 4.8
CVE-2026-14474
HIGH
Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation
CVSS 8.8
CVE-2026-56285
HIGH
Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint
CVSS 8.6
CVE-2026-46386
CRITICAL
OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
CVSS 9.9
CVE-2026-55454
CRITICAL
Appsmith: Caddy admin API exposed without authentication
CVSS 9.9
CVE-2026-54158
CRITICAL
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVSS 9.9
CVE-2026-54067
CRITICAL
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVSS 9.9
CVE-2026-54066
HIGH
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
CVSS 7.5
CVE-2026-48509
CRITICAL
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
CVSS 9.1
CVE-2026-48502
HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-50519
MEDIUM
Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVSS 6.5
CVE-2026-20265
MEDIUM
Insecure Default Domain Allowlist in Splunk AI Toolkit
CVSS 4.3
CVE-2026-0134
LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2026-9262
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Initialization of a Resource with an Insecure Default
CVSS 6.5
Details
Vulnerabilities
312