CWE-1188

Initialization of a Resource with an Insecure Default

Parent: CWE-1419 - Incorrect Initialization of Resource

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

288 vulnerabilities with CWE-1188
CVE-2025-59097 CRITICAL
dormakaba Access Manager 92xx-k5 and 92xx-k7 - Unauthenticated Configuration Manipulation via SOAP Request
CVE-2025-59090 CRITICAL
Kaba exos 9300 < 4.4.0 - Unauthenticated Information Disclosure via SOAP API
CVE-2025-62877 CRITICAL
SUSE Virtualization (Harvester) <1.5.x,1.6.x - Info Disclosure
CVSS 9.8
CVE-2025-5591 MEDIUM
Kentico Xperience 13.0.0-13.0.166 - Stored Cross-Site Scripting via Form Component
CVSS 5.4
CVE-2025-56332 CRITICAL
pangolin < 1.7.0 - Authentication Bypass via Insecure Default Configuration
CVSS 9.1
CVE-2025-14758 MEDIUM
YAOOK 0.20240809.0-0.20251211.0 - Unprotected Database Replication Exposure via MariaDB Misconfiguration
CVSS 6.5
CVE-2025-66482 MEDIUM
Misskey 13.1.0-2025.11.1 - IP Rate Limit Bypass via X-Forwarded-For Header
CVSS 6.5
CVE-2025-64781 MEDIUM
GroupSession <5.7.1 - Open Redirect
CVSS 4.7
CVE-2025-48629 HIGH
VoiceInteractionManagerService - Privilege Escalation
CVSS 7.8
CVE-2025-48621 HIGH
Android - Insecure Default Tapjacking Protection in DefaultTransitionHandler
CVSS 7.3
CVE-2025-66416 HIGH
MCP Python SDK < 1.23.0 - DNS Rebinding Local Server Tool Invocation
CVSS 8.1
CVE-2025-66414 HIGH
MCP TypeScript SDK < 1.24.0 - DNS Rebinding Local Server Tool Invocation
CVSS 8.1
CVE-2025-52622 MEDIUM
HCL BigFix SaaS Remediate - Insecure Default Security Headers
CVSS 5.4
CVE-2025-13357 HIGH
HashiCorp Vault Terraform Provider < 5.5.0 - Insecure Default LDAP Authentication Configuration
CVSS 7.4
CVE-2025-35021 MEDIUM
Abilis CPX Firmware < 9.0.7 - Unauthenticated Authentication Bypass via SSH
CVSS 6.5
CVE-2025-64135 MEDIUM
Jenkins Eggplant Runner Plugin <0.0.1.301.v963cffe8ddb_8 - Info Dis...
CVSS 5.9
CVE-2025-62802 MEDIUM
DNN <10.1.1 - Info Disclosure
CVSS 4.3
CVE-2025-61481 CRITICAL
MikroTik RouterOS <7.14.2 & SwOS <2.18 - XSS
CVSS 10.0
CVE-2025-41245 MEDIUM
VMware Aria Operations - Info Disclosure
CVSS 4.9
CVE-2025-57295 HIGH
H3C Magic NX15 Firmware NX15V100R015 - Unauthenticated Unauthorized Access via Default Credentials
CVSS 8.0
CVE-2025-43797 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.4
CVE-2025-41713 MEDIUM
WAGO Controllers and TP600 Panels - Boot-Time Unauthorized Network Access
CVSS 6.5
CVE-2025-36222 HIGH
IBM Fusion <2.10.1 - Info Disclosure
CVSS 8.7
CVE-2025-59044 MEDIUM
Himmelblau 0.9.0-0.9.22 - Insecure Default Group-to-GID Mapping via Entra ID Display Name
CVSS 4.4
CVE-2025-32330 MEDIUM
Android - Insecure Default Auracast Stream Encryption in LocalBluetoothLeBroadcast
CVSS 5.7
Details
Vulnerabilities 288