CWE-1188 · 263 записей
Initialization of a Resource with an Insecure Default
CVE этого класса
263 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2023-27524Готовый эксплойт | Apache Superset: Session validation vulnerability when using provided default SECRET_KEYapache · superset · CWE-1188 | Критическая9,8 | KEV | 97,4 % | 24 апр. 2023 г. |
97Срочно | CVE-2022-24706Готовый эксплойт | Remote Code Execution Vulnerability in Packagingapache · couchdb · CWE-1188 | Критическая9,8 | KEV | 92,5 % | 26 апр. 2022 г. |
70На этой неделе | CVE-2023-6448Готовый эксплойт | Unitronics VisiLogic uses a default administrative passwordunitronics · vision1210 firmware · CWE-1188 | Критическая9,8 | KEV | 2,1 % | 5 дек. 2023 г. |
62На этой неделе | CVE-2020-11532Готовый эксплойт | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.zohocorp · manageengine adaudit plus · CWE-1188 | Критическая9,8 | — | 77,5 % | 8 мая 2020 г. |
54В плане | CVE-2025-48927Готовый эксплойт | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploitsmarsh · telemessage · CWE-1188 | Средняя5,3 | KEV | 11,1 % | 28 мая 2025 г. |
48В плане | CVE-2020-14011Proof of concept | Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in lansweeper · lansweeper · CWE-1188 | Критическая9,8 | — | 29,5 % | 15 июн. 2020 г. |
47В плане | CVE-2024-2758Эксплойта нет | Tempesta FW rate limits are not enabled by default.tempesta · tempesta fw · CWE-1188 | Средняя6,3 | — | 72,8 % | 3 апр. 2024 г. |
45В плане | CVE-2018-8014Эксплойта нет | The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8apache · tomcat · CWE-1188 | Критическая9,8 | — | 21,3 % | 16 мая 2018 г. |
44В плане | CVE-2021-38759Proof of concept | Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.raspberrypi · raspberry pi os lite · CWE-1188 | Критическая9,8 | — | 15,7 % | 7 дек. 2021 г. |
43В плане | CVE-2017-5178Эксплойта нет | An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and pschneider-electric · tableau desktop · CWE-1188 | Критическая9,8 | — | 13,6 % | 8 мар. 2017 г. |
42В плане | CVE-2021-35336Proof of concept | Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.tieline · ip audtio gateway firmware · CWE-1188 | Критическая9,8 | — | 10,1 % | 1 июл. 2021 г. |
41В плане | CVE-2019-5367Эксплойта нет | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-1188 | Критическая9,8 | — | 8,0 % | 5 июн. 2019 г. |
41В плане | CVE-2017-12739Эксплойта нет | An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi0siemens · sm-2556 firmware · CWE-1188 | Критическая9,8 | — | 5,6 % | 15 нояб. 2017 г. |
41В плане | CVE-2017-7964Эксплойта нет | Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to zyxel · wre6505 firmware · CWE-1188 | Критическая10,0 | — | 2,5 % | 19 апр. 2017 г. |
40В плане | CVE-2019-7252Эксплойта нет | Linear eMerge E3-Series devices have Default Credentials.nortekcontrol · linear emerge essential firmware · CWE-1188 | Критическая9,8 | — | 4,9 % | 2 июл. 2019 г. |
40В плане | CVE-2018-15350Эксплойта нет | Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the roukraftway · 24f2xg router firmware · CWE-1188 | Критическая9,8 | — | 4,7 % | 17 авг. 2018 г. |
40В плане | CVE-2018-19275Эксплойта нет | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remotemitel · cmg suite · CWE-1188 | Критическая9,8 | — | 4,6 % | 2 апр. 2019 г. |
40В плане | CVE-2014-0234Эксплойта нет | The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which redhat · openshift · CWE-1188 | Критическая9,8 | — | 3,8 % | 11 февр. 2020 г. |
40В плане | CVE-2019-5490Эксплойта нет | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enablednetapp · service processor · CWE-1188 | Критическая9,8 | — | 3,5 % | 21 мар. 2019 г. |
40В плане | CVE-2019-14222Proof of concept | An issue was discovered in Alfresco Community Edition versions 6.0 and lower.alfresco · alfresco · CWE-1188 | Критическая9,8 | — | 2,9 % | 5 сент. 2019 г. |
40В плане | CVE-2020-4001Эксплойта нет | The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.vmware · sd-wan orchestrator · CWE-1188 | Критическая9,8 | — | 2,9 % | 24 нояб. 2020 г. |
40В плане | CVE-2019-5497Эксплойта нет | NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that conetapp · aff a700s firmware · CWE-1188 | Критическая9,8 | — | 2,9 % | 1 июл. 2019 г. |
40В плане | CVE-2018-5770Эксплойта нет | An issue was discovered on Tenda AC15 devices.tendacn · ac15 firmware · CWE-1188 | Критическая9,8 | — | 2,7 % | 20 мар. 2018 г. |
40В плане | CVE-2020-27555Эксплойта нет | Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrarbasetech · ge-131 bt-1837836 firmware · CWE-1188 | Критическая9,8 | — | 2,5 % | 17 нояб. 2020 г. |
40В плане | CVE-2019-11618Эксплойта нет | doorGets 7.0 has a default administrator credential vulnerability.doorgets · doorgets cms · CWE-1188 | Критическая9,8 | — | 2,3 % | 30 апр. 2019 г. |
- CVE-2023-2752498Срочно
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %apache · superset24 апр. 2023 г.
- CVE-2022-2470697Срочно
Remote Code Execution Vulnerability in Packaging
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %apache · couchdb26 апр. 2022 г.
- CVE-2023-644870На этой неделе
Unitronics VisiLogic uses a default administrative password
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 2 %unitronics · vision1210 firmware5 дек. 2023 г.
- CVE-2020-1153262На этой неделе
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.
КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %zohocorp · manageengine adaudit plus8 мая 2020 г.
- CVE-2025-4892754В плане
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 11 %smarsh · telemessage28 мая 2025 г.
- CVE-2020-1401148В плане
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in
КритическаяCVSS 9,8Proof of conceptEPSS 29 %lansweeper · lansweeper15 июн. 2020 г.
- CVE-2024-275847В плане
Tempesta FW rate limits are not enabled by default.
СредняяCVSS 6,3Эксплойта нетEPSS 73 %tempesta · tempesta fw3 апр. 2024 г.
- CVE-2018-801445В плане
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8
КритическаяCVSS 9,8Эксплойта нетEPSS 21 %apache · tomcat16 мая 2018 г.
- CVE-2021-3875944В плане
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.
КритическаяCVSS 9,8Proof of conceptEPSS 16 %raspberrypi · raspberry pi os lite7 дек. 2021 г.
- CVE-2017-517843В плане
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and p
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %schneider-electric · tableau desktop8 мар. 2017 г.
- CVE-2021-3533642В плане
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.
КритическаяCVSS 9,8Proof of conceptEPSS 10 %tieline · ip audtio gateway firmware1 июл. 2021 г.
- CVE-2019-536741В плане
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %hp · intelligent management center5 июн. 2019 г.
- CVE-2017-1273941В плане
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi0
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %siemens · sm-2556 firmware15 нояб. 2017 г.
- CVE-2017-796441В плане
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %zyxel · wre6505 firmware19 апр. 2017 г.
- CVE-2019-725240В плане
Linear eMerge E3-Series devices have Default Credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2018-1535040В плане
Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the rou
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %kraftway · 24f2xg router firmware17 авг. 2018 г.
- CVE-2018-1927540В плане
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mitel · cmg suite2 апр. 2019 г.
- CVE-2014-023440В плане
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %redhat · openshift11 февр. 2020 г.
- CVE-2019-549040В плане
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %netapp · service processor21 мар. 2019 г.
- CVE-2019-1422240В плане
An issue was discovered in Alfresco Community Edition versions 6.0 and lower.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %alfresco · alfresco5 сент. 2019 г.
- CVE-2020-400140В плане
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %vmware · sd-wan orchestrator24 нояб. 2020 г.
- CVE-2019-549740В плане
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that co
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %netapp · aff a700s firmware1 июл. 2019 г.
- CVE-2018-577040В плане
An issue was discovered on Tenda AC15 devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %tendacn · ac15 firmware20 мар. 2018 г.
- CVE-2020-2755540В плане
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrar
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %basetech · ge-131 bt-1837836 firmware17 нояб. 2020 г.
- CVE-2019-1161840В плане
doorGets 7.0 has a default administrator credential vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %doorgets · doorgets cms30 апр. 2019 г.