VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (345)

page 17 of 18
  • CVE-2025-62802MedOct 28, 2025
    risk 0.21cvss 4.3epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is…

  • CVE-2022-20342LowAug 12, 2022
    risk 0.21cvss 3.3epss 0.00

    In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-26930LowOct 9, 2020
    risk 0.21cvss 3.3epss 0.01

    NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.

  • CVE-2025-27443LowApr 8, 2025
    risk 0.18cvss 2.8epss 0.00

    Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.

  • CVE-2024-56433LowDec 26, 2024
    risk 0.16cvss 3.6epss 0.00

    shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account…

  • CVE-2026-55708LowJul 22, 2026
    risk 0.13cvss 3.1epss 0.00

    In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the…

  • CVE-2023-3485LowJun 30, 2023
    risk 0.13cvss 3.0epss 0.00

    Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done outside of the normal Temporal server…

  • CVE-2024-34063LowMay 3, 2024
    risk 0.09cvss 2.5epss 0.00

    vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes in third-party cryptographic dependencies (the Dalek crates), which moved secret zeroization capabilities behind a…

  • CVE-2024-51758LowNov 7, 2024
    risk 0.08cvss —epss 0.01

    Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driver to something production-ready like…

  • CVE-2021-41192HigNov 24, 2021
    risk 0.01cvss 8.1epss 0.08

    Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all…

  • CVE-2026-63563MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document…

  • CVE-2026-62416MedAug 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without…

  • CVE-2026-67208CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.05

    Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected…

  • CVE-2026-65881HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.

  • CVE-2026-9680MedJul 28, 2026
    risk 0.00cvss 5.8epss 0.00

    Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

  • CVE-2026-62415CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

  • CVE-2026-60024CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

  • CVE-2026-62185HigJul 13, 2026
    risk 0.00cvss 7.6epss 0.00

    Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code…

  • CVE-2026-61439HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.00

    PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction…

  • CVE-2026-56285HigJun 29, 2026
    risk 0.00cvss 8.6epss 0.00

    Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers can retrieve HTTP responses from any host reachable by the…