CWE-1188

Initialization of a Resource with an Insecure Default

Parent: CWE-1419 - Incorrect Initialization of Resource

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

261 vulnerabilities with CWE-1188
CVE-2024-56433 LOW
shadow-utils 4.4-4.17.0 - Privilege Escalation
CVSS 3.6
CVE-2024-51758 LOW
Filament - Info Disclosure
CVE-2024-9949 MEDIUM
Forescout SecureConnector 11.1.02.1019 - DoS
CVSS 6.1
CVE-2024-30124 MEDIUM
HCL Sametime - Info Disclosure
CVSS 4.0
CVE-2024-45217 HIGH
Apache Solr - Insecure Default Initialization of Resource
CVSS 8.1
CVE-2024-47295 HIGH
SEIKO EPSON Web Config - RCE
CVSS 8.1
CVE-2024-0001 CRITICAL
FlashArray Purity - Privilege Escalation
CVSS 10.0
CVE-2024-44096 MEDIUM
Google Android - Information Disclosure
CVSS 4.4
CVE-2024-8383 HIGH
Firefox - Open Redirect
CVSS 7.5
CVE-2024-45313 MEDIUM
Overleaf - Info Disclosure
CVSS 5.4
CVE-2024-34734 HIGH
FooterActionsViewModel - Privilege Escalation
CVSS 7.8
CVE-2024-5801 MEDIUM
B&R Automation Runtime <6.0.2 - SSRF
CVE-2024-41995 HIGH
JavaTM Platform <12.89 - Info Disclosure
CVSS 7.5
CVE-2024-31070 CRITICAL
FutureNet NXR/WXR/VXR - Info Disclosure
CVSS 9.1
CVE-2024-39916 MEDIUM
FOG - Info Disclosure
CVSS 6.4
CVE-2024-34063 LOW
vodozemac 0.5.0-0.5.1 - Memory Corruption
CVSS 2.5
CVE-2024-32114 HIGH
Apache ActiveMQ 6.x - Info Disclosure
CVSS 8.5
CVE-2024-2912 CRITICAL
BentoML - RCE
CVSS 10.0
CVE-2024-28815 CRITICAL
Mitel InAttend <2.7 - Info Disclosure
CVSS 9.8
CVE-2024-25972 HIGH
OET-213H-BTS1 - Info Disclosure
CVSS 8.3
CVE-2024-0387 MEDIUM
EDS-4000/G4000 Series <3.2 - SSRF
CVSS 6.5
CVE-2024-26267 MEDIUM
Liferay Portal <7.4.3.25, Liferay DXP <7.4 - Info Disclosure
CVSS 5.3
CVE-2024-25610 CRITICAL
Liferay Portal <7.4.3.12 & DXP <7.2 - XSS
CVSS 9.0
CVE-2024-22388 MEDIUM
Encoder Configuration - Info Disclosure
CVSS 5.9
CVE-2024-22207 MEDIUM
Fastify Swagger-UI - Information Disclosure
CVSS 5.3
Details
Vulnerabilities 261