CWE-453 · 20 records
Insecure Default Variable Initialization
CVEs in this class
20 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-0082No exploit | In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure defaultgoogle · android · CWE-453 | Critical10.0 | — | 0.2% | Jun 17, 2026 |
39Monitor | CVE-2021-27426No exploit | GE UR family insecure default variable initializationge · multilin b30 firmware · CWE-453 | Critical9.8 | — | 1.2% | Mar 23, 2022 |
39Monitor | CVE-2025-47945No exploit | Donetick Has Weak Default JWT Secretdonetick · donetick · CWE-453 | Critical9.8 | — | 0.7% | May 17, 2025 |
37Monitor | CVE-2026-92950No exploit | vm2 before 3.11.7 Sandbox Escape via CLI requirepatriksimek · vm2 · CWE-453 | Critical9.3 | — | 0.2% | Sep 17, 2026 |
36Monitor | CVE-2024-21411No exploit | Skype for Consumer Remote Code Execution Vulnerabilityskype · skype · CWE-453 | High8.8 | — | 2.6% | Mar 12, 2024 |
32Monitor | CVE-2024-49120No exploit | Windows Remote Desktop Services Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-453 | High8.1 | — | 1.1% | Dec 11, 2024 |
32Monitor | CVE-2022-3262No exploit | A flaw was found in Openshift.redhat · openshift · CWE-453 | High8.1 | — | 0.7% | Dec 8, 2022 |
31Monitor | CVE-2023-27516No exploit | An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.softether · vpn · CWE-453 | High7.8 | — | 0.5% | Oct 12, 2023 |
31Monitor | CVE-2025-48563No exploit | In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.google · android · CWE-453 | High7.8 | — | 0.1% | Sep 4, 2025 |
30Monitor | CVE-2024-41255No exploit | filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a manfilestash · filestash · CWE-453 | High7.5 | — | 0.3% | Jul 31, 2024 |
25Monitor | CVE-2024-39916No exploit | NFS server misconfiguration allows file access outside the exported directoryfogproject · fogproject · CWE-453 | Medium6.4 | — | 0.3% | Jul 12, 2024 |
21Monitor | CVE-2022-47197No exploit | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Medium5.4 | — | 1.0% | Jan 19, 2023 |
21Monitor | CVE-2022-47194No exploit | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Medium5.4 | — | 0.8% | Jan 19, 2023 |
21Monitor | CVE-2022-47195No exploit | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Medium5.4 | — | 0.7% | Jan 19, 2023 |
21Monitor | CVE-2022-47196No exploit | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Medium5.4 | — | 0.7% | Jan 19, 2023 |
19Monitor | CVE-2022-46831No exploit | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity projectjetbrains · teamcity · CWE-453 | Medium4.9 | — | 0.5% | Dec 8, 2022 |
18Monitor | CVE-2025-61926No exploit | Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secretossf · allstar · CWE-453 | Medium4.6 | — | 0.4% | Oct 9, 2025 |
14Monitor | GHSA-879p-8gw4-mcpwNo exploit | fgr Vulnerable to Insecure Default Variable InitializationPyPI · fgr · CWE-453 | Low3.7 | — | — | Mar 15, 2024 |
8Monitor | CVE-2026-19212No exploit | WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variableCWE-453 | Low2.1 | — | 0.5% | Aug 7, 2026 |
8Monitor | CVE-2026-41330No exploit | OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policyopenclaw · openclaw · CWE-453 | Low2.0 | — | 0.2% | Apr 20, 2026 |
- CVE-2026-008240Plan
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default
CriticalCVSS 10.0No exploitEPSS 0%google · androidJun 17, 2026
- CVE-2021-2742639Monitor
GE UR family insecure default variable initialization
CriticalCVSS 9.8No exploitEPSS 1%ge · multilin b30 firmwareMar 23, 2022
- CVE-2025-4794539Monitor
Donetick Has Weak Default JWT Secret
CriticalCVSS 9.8No exploitEPSS 1%donetick · donetickMay 17, 2025
- CVE-2026-9295037Monitor
vm2 before 3.11.7 Sandbox Escape via CLI require
CriticalCVSS 9.3No exploitEPSS 0%patriksimek · vm2Sep 17, 2026
- CVE-2024-2141136Monitor
Skype for Consumer Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 3%skype · skypeMar 12, 2024
- CVE-2024-4912032Monitor
Windows Remote Desktop Services Remote Code Execution Vulnerability
HighCVSS 8.1No exploitEPSS 1%microsoft · windows server 2012Dec 11, 2024
- CVE-2022-326232Monitor
A flaw was found in Openshift.
HighCVSS 8.1No exploitEPSS 1%redhat · openshiftDec 8, 2022
- CVE-2023-2751631Monitor
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.
HighCVSS 7.8No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2025-4856331Monitor
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.
HighCVSS 7.8No exploitEPSS 0%google · androidSep 4, 2025
- CVE-2024-4125530Monitor
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man
HighCVSS 7.5No exploitEPSS 0%filestash · filestashJul 31, 2024
- CVE-2024-3991625Monitor
NFS server misconfiguration allows file access outside the exported directory
MediumCVSS 6.4No exploitEPSS 0%fogproject · fogprojectJul 12, 2024
- CVE-2022-4719721Monitor
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
MediumCVSS 5.4No exploitEPSS 1%ghost · ghostJan 19, 2023
- CVE-2022-4719421Monitor
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
MediumCVSS 5.4No exploitEPSS 1%ghost · ghostJan 19, 2023
- CVE-2022-4719521Monitor
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
MediumCVSS 5.4No exploitEPSS 1%ghost · ghostJan 19, 2023
- CVE-2022-4719621Monitor
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
MediumCVSS 5.4No exploitEPSS 1%ghost · ghostJan 19, 2023
- CVE-2022-4683119Monitor
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project
MediumCVSS 4.9No exploitEPSS 0%jetbrains · teamcityDec 8, 2022
- CVE-2025-6192618Monitor
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
MediumCVSS 4.6No exploitEPSS 0%ossf · allstarOct 9, 2025
- GHSA-879p-8gw4-mcpw14Monitor
fgr Vulnerable to Insecure Default Variable Initialization
LowCVSS 3.7No exploitPyPI · fgrMar 15, 2024
- CVE-2026-192128Monitor
WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
LowCVSS 2.1No exploitEPSS 0%Aug 7, 2026
- CVE-2026-413308Monitor
OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
LowCVSS 2.0No exploitEPSS 0%openclaw · openclawApr 20, 2026