Перейти к содержимому
Noroxi

CWE-1188 · 263 записей

Initialization of a Resource with an Insecure Default

CVE этого класса

263 записей

  • CVE-2023-27524
    98Срочно

    Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    apache · superset24 апр. 2023 г.

  • CVE-2022-24706
    97Срочно

    Remote Code Execution Vulnerability in Packaging

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %

    apache · couchdb26 апр. 2022 г.

  • CVE-2023-6448
    70На этой неделе

    Unitronics VisiLogic uses a default administrative password

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 2 %

    unitronics · vision1210 firmware5 дек. 2023 г.

  • CVE-2020-11532
    62На этой неделе

    Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %

    zohocorp · manageengine adaudit plus8 мая 2020 г.

  • CVE-2025-48927
    54В плане

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit

    СредняяCVSS 5,3KEVГотовый эксплойтEPSS 11 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2020-14011
    48В плане

    Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in

    КритическаяCVSS 9,8Proof of conceptEPSS 29 %

    lansweeper · lansweeper15 июн. 2020 г.

  • CVE-2024-2758
    47В плане

    Tempesta FW rate limits are not enabled by default.

    СредняяCVSS 6,3Эксплойта нетEPSS 73 %

    tempesta · tempesta fw3 апр. 2024 г.

  • CVE-2018-8014
    45В плане

    The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8

    КритическаяCVSS 9,8Эксплойта нетEPSS 21 %

    apache · tomcat16 мая 2018 г.

  • CVE-2021-38759
    44В плане

    Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.

    КритическаяCVSS 9,8Proof of conceptEPSS 16 %

    raspberrypi · raspberry pi os lite7 дек. 2021 г.

  • CVE-2017-5178
    43В плане

    An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and p

    КритическаяCVSS 9,8Эксплойта нетEPSS 14 %

    schneider-electric · tableau desktop8 мар. 2017 г.

  • CVE-2021-35336
    42В плане

    Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.

    КритическаяCVSS 9,8Proof of conceptEPSS 10 %

    tieline · ip audtio gateway firmware1 июл. 2021 г.

  • CVE-2019-5367
    41В плане

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    hp · intelligent management center5 июн. 2019 г.

  • CVE-2017-12739
    41В плане

    An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi0

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    siemens · sm-2556 firmware15 нояб. 2017 г.

  • CVE-2017-7964
    41В плане

    Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    zyxel · wre6505 firmware19 апр. 2017 г.

  • CVE-2019-7252
    40В плане

    Linear eMerge E3-Series devices have Default Credentials.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    nortekcontrol · linear emerge essential firmware2 июл. 2019 г.

  • CVE-2018-15350
    40В плане

    Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the rou

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    kraftway · 24f2xg router firmware17 авг. 2018 г.

  • CVE-2018-19275
    40В плане

    The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    mitel · cmg suite2 апр. 2019 г.

  • CVE-2014-0234
    40В плане

    The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    redhat · openshift11 февр. 2020 г.

  • CVE-2019-5490
    40В плане

    Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    netapp · service processor21 мар. 2019 г.

  • CVE-2019-14222
    40В плане

    An issue was discovered in Alfresco Community Edition versions 6.0 and lower.

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    alfresco · alfresco5 сент. 2019 г.

  • CVE-2020-4001
    40В плане

    The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    vmware · sd-wan orchestrator24 нояб. 2020 г.

  • CVE-2019-5497
    40В плане

    NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that co

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    netapp · aff a700s firmware1 июл. 2019 г.

  • CVE-2018-5770
    40В плане

    An issue was discovered on Tenda AC15 devices.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    tendacn · ac15 firmware20 мар. 2018 г.

  • CVE-2020-27555
    40В плане

    Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrar

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    basetech · ge-131 bt-1837836 firmware17 нояб. 2020 г.

  • CVE-2019-11618
    40В плане

    doorGets 7.0 has a default administrator credential vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    doorgets · doorgets cms30 апр. 2019 г.

Все классы уязвимостей