CWE-1188

Initialization of a Resource with an Insecure Default

Parent: CWE-1419 - Incorrect Initialization of Resource

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

288 vulnerabilities with CWE-1188
CVE-2020-26930 LOW
NETGEAR EX7700 <1.0.0.210 - Info Disclosure
CVSS 3.3
CVE-2020-24365 HIGH
Gemtek WRTM-127ACN/WRTM-127x9 - Command Injection
CVSS 8.8
CVE-2020-0271 HIGH
Android 11 - Local Privilege Escalation and Tapjacking via Insecure Default Setting
CVSS 7.3
CVE-2020-0394 HIGH
Android - Tapjacking via BluetoothPairingDialog Insecure Default
CVSS 7.8
CVE-2020-0386 MEDIUM
Android - Local Privilege Escalation via Tapjacking in RequestPermissionActivity
CVSS 5.5
CVE-2020-16873 MEDIUM
Microsoft Xamarin.Forms <83.0.4103.106 - SSRF
CVSS 4.7
CVE-2020-7729 HIGH
grunt < 1.3.0 - Arbitrary Code Execution via Insecure YAML Deserialization
CVSS 7.1
CVE-2020-7685 MEDIUM
Umbraco Forms - Insecure Default File Upload Configuration
CVSS 5.4
CVE-2020-10279 CRITICAL
MiR and ER Robot Firmware < 2.8.1.1 - Race Condition and Privilege Escalation via Insecure Ubuntu Defaults
CVSS 9.8
CVE-2020-14011 CRITICAL
Lansweeper <7.2.x - Command Injection
CVSS 9.8
CVE-2020-11532 CRITICAL
ManageEngine ADAudit Plus Xnode Enumeration
CVSS 9.8
CVE-2020-8828 HIGH
Argocd-server <1.5.0 - Privilege Escalation
CVSS 8.8
CVE-2019-25219 HIGH
Asio C++ Library <1.13.0 - Info Disclosure
CVSS 7.5
CVE-2019-20470 HIGH
TK-Star Q90 Junior GPS Horloge Firmware 3.1042.9.8656 - Unauthenticated SMS Command Injection via Default Password
CVSS 7.5
CVE-2019-13393 HIGH
Voo NETGEAR CG3700b V2.02.03 - Info Disclosure
CVSS 7.5
CVE-2019-17274 HIGH
NetApp FAS 8300/8700 and AFF A400 BMC - Command Injection
CVSS 7.8
CVE-2019-1950 HIGH
Cisco IOS XE SD-WAN - Privilege Escalation
CVSS 8.4
CVE-2019-16272 CRITICAL
DTEN D5-D7 <1.3.4 - Info Disclosure
CVSS 9.8
CVE-2019-19340 HIGH
Ansible Tower <3.6.2-3.5.3 - Privilege Escalation
CVSS 8.2
CVE-2019-19251 MEDIUM
Last.fm Scrobbler <2.1.39 - Info Disclosure
CVSS 5.3
CVE-2019-4621 CRITICAL
IBM DataPower Gateway - Privilege Escalation
CVSS 9.8
CVE-2019-2197 MEDIUM
Android 8.0-10 - Local Information Disclosure via CachedBluetoothDevice Insecure Default
CVSS 5.5
CVE-2019-16102 CRITICAL
Silver Peak EdgeConnect <8.1.7.x - Info Disclosure
CVSS 9.8
CVE-2019-14222 CRITICAL
Alfresco Community Edition <=6.0 - Auth Bypass
CVSS 9.8
CVE-2019-4169 CRITICAL
IBM Open Power Firmware - Privilege Escalation
CVSS 9.1
Details
Vulnerabilities 288