VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (345)

page 15 of 18
  • CVE-2022-47194MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2020-7685MedJul 28, 2020
    risk 0.35cvss 5.4epss 0.01

    This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package can create a custom workflow and frontend…

  • CVE-2019-19251MedDec 10, 2019
    risk 0.35cvss 5.3epss 0.01

    The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.

  • CVE-2017-5491MedJan 15, 2017
    risk 0.35cvss 5.3epss 0.03

    wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

  • CVE-2026-93338MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with the default community string 'public'.…

  • CVE-2026-33921MedAug 11, 2026
    risk 0.34cvss 5.2epss 0.00

    The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the…

  • CVE-2025-32378MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double…

  • CVE-2024-41975MedMar 18, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.

  • CVE-2024-5801MedAug 12, 2024
    risk 0.34cvss —epss 0.00

    Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.

  • CVE-2023-28978MedApr 17, 2023
    risk 0.34cvss 5.3epss 0.00

    An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information. In the default configuration it is possible to read confidential information about…

  • CVE-2022-48432MedMar 29, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.

  • CVE-2022-48342MedFeb 23, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

  • CVE-2022-36349MedNov 11, 2022
    risk 0.34cvss 5.2epss 0.00

    Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-41245MedSep 29, 2025
    risk 0.32cvss 4.9epss 0.01

    VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.

  • CVE-2026-54800MedJul 9, 2026
    risk 0.31cvss 4.8epss 0.00

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an…

  • CVE-2025-64781MedDec 12, 2025
    risk 0.31cvss 4.7epss 0.00

    In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to "Do not limit" in the initial configuration. With this configuration, the user may be redirected to an…

  • CVE-2020-16873MedSep 11, 2020
    risk 0.31cvss 4.7epss 0.04

    A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system. For the attack to be…

  • CVE-2025-2441MedApr 9, 2025
    risk 0.30cvss 4.6epss 0.00

    CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.

  • CVE-2021-33130MedMay 12, 2022
    risk 0.30cvss 4.6epss 0.00

    Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.

  • CVE-2024-44096MedSep 13, 2024
    risk 0.29cvss 4.4epss 0.00

    there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.