VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (330)

page 14 of 17
  • CVE-2025-52622MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable to common web attacks that these headers are designed to mitigate, such as Cross-Site Scripting…

  • CVE-2025-43797MedSep 15, 2025
    risk 0.35cvss 5.4epss 0.00

    In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is “Open” which allows any registered…

  • CVE-2024-39916MedJul 12, 2024
    risk 0.35cvss 6.4epss 0.00

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that allows an attacker to modify files outside the export in the default installation. The exports…

  • CVE-2023-33949MedMay 24, 2023
    risk 0.35cvss 5.3epss 0.01

    In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The…

  • CVE-2023-31101MedMay 22, 2023
    risk 0.35cvss 6.5epss 0.01

    Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache…

  • CVE-2022-47196MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2022-47194MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2020-7685MedJul 28, 2020
    risk 0.35cvss 5.4epss 0.01

    This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend…

  • CVE-2019-19251MedDec 10, 2019
    risk 0.35cvss 5.3epss 0.01

    The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.

  • CVE-2017-5491MedJan 15, 2017
    risk 0.35cvss 5.3epss 0.03

    wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

  • CVE-2026-33921MedAug 11, 2026
    risk 0.34cvss 5.2epss 0.00

    The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the…

  • CVE-2025-32378MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double…

  • CVE-2024-41975MedMar 18, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.

  • CVE-2024-5801MedAug 12, 2024
    risk 0.34cvss epss 0.00

    Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.

  • CVE-2023-28978MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.00

    An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information. In the default configuration it is possible to read confidential information about…

  • CVE-2022-48432MedMar 29, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.

  • CVE-2022-48342MedFeb 23, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

  • CVE-2022-36349MedNov 11, 2022
    risk 0.34cvss 5.2epss 0.00

    Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-41245MedSep 29, 2025
    risk 0.32cvss 4.9epss 0.01

    VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.

  • CVE-2026-54800MedJul 9, 2026
    risk 0.31cvss 4.8epss 0.00

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an…