VYPR

CWE-453

Insecure Default Variable Initialization

VariantDraft

Description

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (21)

page 1 of 2
  • CVE-2021-27426CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

  • CVE-2025-30206CriApr 15, 2025
    risk 0.57cvss 9.8epss 0.01

    Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine. This security flaw…

  • CVE-2024-21411HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.03

    Skype for Consumer Remote Code Execution Vulnerability

  • CVE-2024-49120HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2022-3262HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

  • CVE-2026-0082HigJun 17, 2026
    risk 0.51cvss 7.8epss 0.00

    In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-48563HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-41255HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.00

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.

  • CVE-2023-27516HigOct 12, 2023
    risk 0.47cvss 7.3epss 0.01

    An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-46831MedDec 8, 2022
    risk 0.43cvss 6.6epss 0.00

    In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

  • CVE-2024-39916MedJul 12, 2024
    risk 0.35cvss 6.4epss 0.00

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that allows an attacker to modify files outside the export in the default installation. The exports…

  • CVE-2022-47197MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2022-47196MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2022-47195MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2022-47194MedJan 19, 2023
    risk 0.35cvss 5.4epss 0.01

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To…

  • CVE-2026-19212MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType can lead to use of uninitialized…

  • CVE-2020-28481MedJan 19, 2021
    risk 0.28cvss 5.3epss 0.01

    The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

  • CVE-2025-61926MedOct 9, 2025
    risk 0.23cvss epss 0.00

    Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into…

  • CVE-2026-41330MedApr 21, 2026
    risk 0.22cvss 4.4epss 0.00

    OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables to circumvent proxy settings,…

  • CVE-2008-6540Mar 30, 2009
    risk 0.03cvss epss 0.03

    DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the…