Перейти к содержимому
Noroxi

CWE-453 · 20 записей

Insecure Default Variable Initialization

CVE этого класса

20 записей

  • CVE-2026-0082
    40В плане

    In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    google · android17 июн. 2026 г.

  • CVE-2021-27426
    39Наблюдать

    GE UR family insecure default variable initialization

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ge · multilin b30 firmware23 мар. 2022 г.

  • CVE-2025-47945
    39Наблюдать

    Donetick Has Weak Default JWT Secret

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    donetick · donetick17 мая 2025 г.

  • CVE-2026-92950
    37Наблюдать

    vm2 before 3.11.7 Sandbox Escape via CLI require

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    patriksimek · vm217 сент. 2026 г.

  • CVE-2024-21411
    36Наблюдать

    Skype for Consumer Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    skype · skype12 мар. 2024 г.

  • CVE-2024-49120
    32Наблюдать

    Windows Remote Desktop Services Remote Code Execution Vulnerability

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    microsoft · windows server 201211 дек. 2024 г.

  • CVE-2022-3262
    32Наблюдать

    A flaw was found in Openshift.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    redhat · openshift8 дек. 2022 г.

  • CVE-2023-27516
    31Наблюдать

    An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    softether · vpn12 окт. 2023 г.

  • CVE-2025-48563
    31Наблюдать

    In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    google · android4 сент. 2025 г.

  • CVE-2024-41255
    30Наблюдать

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    filestash · filestash31 июл. 2024 г.

  • CVE-2024-39916
    25Наблюдать

    NFS server misconfiguration allows file access outside the exported directory

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    fogproject · fogproject12 июл. 2024 г.

  • CVE-2022-47197
    21Наблюдать

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    ghost · ghost19 янв. 2023 г.

  • CVE-2022-47194
    21Наблюдать

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    ghost · ghost19 янв. 2023 г.

  • CVE-2022-47195
    21Наблюдать

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    ghost · ghost19 янв. 2023 г.

  • CVE-2022-47196
    21Наблюдать

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    ghost · ghost19 янв. 2023 г.

  • CVE-2022-46831
    19Наблюдать

    In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    jetbrains · teamcity8 дек. 2022 г.

  • CVE-2025-61926
    18Наблюдать

    Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    ossf · allstar9 окт. 2025 г.

  • GHSA-879p-8gw4-mcpw
    14Наблюдать

    fgr Vulnerable to Insecure Default Variable Initialization

    НизкаяCVSS 3,7Эксплойта нет

    PyPI · fgr15 мар. 2024 г.

  • CVE-2026-19212
    8Наблюдать

    WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable

    НизкаяCVSS 2,1Эксплойта нетEPSS 0 %

    7 авг. 2026 г.

  • CVE-2026-41330
    8Наблюдать

    OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy

    НизкаяCVSS 2,0Эксплойта нетEPSS 0 %

    openclaw · openclaw20 апр. 2026 г.

Все классы уязвимостей