CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
288 vulnerabilities with CWE-1188
CVE-2024-22388
MEDIUM
Encoder Configuration - Info Disclosure
CVSS 5.9
CVE-2024-22207
MEDIUM
Fastify Swagger-UI - Information Disclosure
CVSS 5.3
CVE-2023-48733
MEDIUM
Canonical LXD - Insecure Default UEFI Shell Configuration
CVSS 6.7
CVE-2023-6448
CRITICAL
KEV
Unitronics VisiLogic <9.9.00 - Info Disclosure
CVSS 9.8
CVE-2023-27516
HIGH
SoftEther VPN 4.41-9782-beta and 5.01.9674 - Authentication Bypass via CiRpcAccepted()
CVSS 7.3
CVE-2023-45312
HIGH
mtproto/mt_proto_proxy < 0.7.2 - Unauthenticated Remote Code Execution
CVSS 8.8
CVE-2023-5368
MEDIUM
FreeBSD - Uninitialized Data Exposure via msdosfs Truncate Operations
CVSS 6.5
CVE-2023-40708
MEDIUM
SNAP PAC S1 Firmware <R10.3b - Info Disclosure
CVSS 5.8
CVE-2023-3453
HIGH
ETIC Telecom RAS <4.7.0 - DoS
CVSS 7.1
CVE-2023-35689
HIGH
Android - Local Privilege Escalation via Insecure ADB Default in DeviceVersionFragment
CVSS 7.8
CVE-2023-3485
LOW
Temporal Server < 1.20.0 - Namespace Access Control Bypass via Crafted Task Token
CVSS 3.0
CVE-2023-33949
MEDIUM
Liferay Portal <7.3.0 & Liferay DXP <7.2 - Info Disclosure
CVSS 5.3
CVE-2023-31101
MEDIUM
Apache InLong <1.7.0 - Info Disclosure
CVSS 6.5
CVE-2023-1618
HIGH
Mitsubishi Electric MELSEC WS Series - Auth Bypass
CVSS 7.5
CVE-2023-27524
HIGH
KEV
Apache Superset Signed Cookie Priv Esc
CVSS 8.9
CVE-2023-28978
MEDIUM
Juniper Networks Junos OS Evolved <20.4R3-S7-EVO, <21.1R3-S4-EVO - ...
CVSS 5.3
CVE-2022-49099
MEDIUM
Linux Kernel 5.17 - Insecure Default Resource Initialization in vmbus_device_register()
CVSS 5.5
CVE-2022-48493
HIGH
Huawei EMUI - Denial of Service via Secure OS Module Configuration Defects
CVSS 7.5
CVE-2022-48492
HIGH
Huawei EMUI - Denial of Service via Secure OS Module Configuration Defects
CVSS 7.5
CVE-2022-48432
MEDIUM
JetBrains IntelliJ IDEA <2023.1 - Info Disclosure
CVSS 5.2
CVE-2022-38745
HIGH
Apache OpenOffice <4.1.14 - Code Injection
CVSS 7.8
CVE-2022-4224
HIGH
CODESYS Control for Beaglebone SL 3.0-4.8.0.0 - Unauthenticated Arbitrary File Read/Write and Denial of Service
CVSS 8.8
CVE-2022-48342
MEDIUM
JetBrains TeamCity <2022.10.2 - Info Disclosure
CVSS 5.2
CVE-2022-47196
MEDIUM
Ghost Foundation Ghost 5.9.4 - Privilege Escalation
CVSS 5.4
CVE-2022-47194
MEDIUM
Ghost Foundation Ghost 5.9.4 - Privilege Escalation
CVSS 5.4
Details
Vulnerabilities
288