Skip to content
Noroxi

CWE-453 · 20 records

Insecure Default Variable Initialization

CVEs in this class

20 records

  • In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default

    CriticalCVSS 10.0No exploitEPSS 0%

    google · androidJun 17, 2026

  • GE UR family insecure default variable initialization

    CriticalCVSS 9.8No exploitEPSS 1%

    ge · multilin b30 firmwareMar 23, 2022

  • Donetick Has Weak Default JWT Secret

    CriticalCVSS 9.8No exploitEPSS 1%

    donetick · donetickMay 17, 2025

  • vm2 before 3.11.7 Sandbox Escape via CLI require

    CriticalCVSS 9.3No exploitEPSS 0%

    patriksimek · vm2Sep 17, 2026

  • Skype for Consumer Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 3%

    skype · skypeMar 12, 2024

  • Windows Remote Desktop Services Remote Code Execution Vulnerability

    HighCVSS 8.1No exploitEPSS 1%

    microsoft · windows server 2012Dec 11, 2024

  • CVE-2022-3262
    32Monitor

    A flaw was found in Openshift.

    HighCVSS 8.1No exploitEPSS 1%

    redhat · openshiftDec 8, 2022

  • An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.

    HighCVSS 7.8No exploitEPSS 1%

    softether · vpnOct 12, 2023

  • In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.

    HighCVSS 7.8No exploitEPSS 0%

    google · androidSep 4, 2025

  • filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man

    HighCVSS 7.5No exploitEPSS 0%

    filestash · filestashJul 31, 2024

  • NFS server misconfiguration allows file access outside the exported directory

    MediumCVSS 6.4No exploitEPSS 0%

    fogproject · fogprojectJul 12, 2024

  • An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    MediumCVSS 5.4No exploitEPSS 1%

    ghost · ghostJan 19, 2023

  • An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    MediumCVSS 5.4No exploitEPSS 1%

    ghost · ghostJan 19, 2023

  • An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    MediumCVSS 5.4No exploitEPSS 1%

    ghost · ghostJan 19, 2023

  • An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    MediumCVSS 5.4No exploitEPSS 1%

    ghost · ghostJan 19, 2023

  • In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project

    MediumCVSS 4.9No exploitEPSS 0%

    jetbrains · teamcityDec 8, 2022

  • Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

    MediumCVSS 4.6No exploitEPSS 0%

    ossf · allstarOct 9, 2025

  • fgr Vulnerable to Insecure Default Variable Initialization

    LowCVSS 3.7No exploit

    PyPI · fgrMar 15, 2024

  • WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable

    LowCVSS 2.1No exploitEPSS 0%

    Aug 7, 2026

  • OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy

    LowCVSS 2.0No exploitEPSS 0%

    openclaw · openclawApr 20, 2026

All vulnerability classes