CWE-453 · 20 записей
Insecure Default Variable Initialization
CVE этого класса
20 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2026-0082Эксплойта нет | In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure defaultgoogle · android · CWE-453 | Критическая10,0 | — | 0,2 % | 17 июн. 2026 г. |
39Наблюдать | CVE-2021-27426Эксплойта нет | GE UR family insecure default variable initializationge · multilin b30 firmware · CWE-453 | Критическая9,8 | — | 1,2 % | 23 мар. 2022 г. |
39Наблюдать | CVE-2025-47945Эксплойта нет | Donetick Has Weak Default JWT Secretdonetick · donetick · CWE-453 | Критическая9,8 | — | 0,7 % | 17 мая 2025 г. |
37Наблюдать | CVE-2026-92950Эксплойта нет | vm2 before 3.11.7 Sandbox Escape via CLI requirepatriksimek · vm2 · CWE-453 | Критическая9,3 | — | 0,2 % | 17 сент. 2026 г. |
36Наблюдать | CVE-2024-21411Эксплойта нет | Skype for Consumer Remote Code Execution Vulnerabilityskype · skype · CWE-453 | Высокая8,8 | — | 2,6 % | 12 мар. 2024 г. |
32Наблюдать | CVE-2024-49120Эксплойта нет | Windows Remote Desktop Services Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-453 | Высокая8,1 | — | 1,1 % | 11 дек. 2024 г. |
32Наблюдать | CVE-2022-3262Эксплойта нет | A flaw was found in Openshift.redhat · openshift · CWE-453 | Высокая8,1 | — | 0,7 % | 8 дек. 2022 г. |
31Наблюдать | CVE-2023-27516Эксплойта нет | An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.softether · vpn · CWE-453 | Высокая7,8 | — | 0,5 % | 12 окт. 2023 г. |
31Наблюдать | CVE-2025-48563Эксплойта нет | In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.google · android · CWE-453 | Высокая7,8 | — | 0,1 % | 4 сент. 2025 г. |
30Наблюдать | CVE-2024-41255Эксплойта нет | filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a manfilestash · filestash · CWE-453 | Высокая7,5 | — | 0,3 % | 31 июл. 2024 г. |
25Наблюдать | CVE-2024-39916Эксплойта нет | NFS server misconfiguration allows file access outside the exported directoryfogproject · fogproject · CWE-453 | Средняя6,4 | — | 0,3 % | 12 июл. 2024 г. |
21Наблюдать | CVE-2022-47197Эксплойта нет | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Средняя5,4 | — | 1,0 % | 19 янв. 2023 г. |
21Наблюдать | CVE-2022-47194Эксплойта нет | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Средняя5,4 | — | 0,8 % | 19 янв. 2023 г. |
21Наблюдать | CVE-2022-47195Эксплойта нет | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Средняя5,4 | — | 0,7 % | 19 янв. 2023 г. |
21Наблюдать | CVE-2022-47196Эксплойта нет | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Средняя5,4 | — | 0,7 % | 19 янв. 2023 г. |
19Наблюдать | CVE-2022-46831Эксплойта нет | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity projectjetbrains · teamcity · CWE-453 | Средняя4,9 | — | 0,5 % | 8 дек. 2022 г. |
18Наблюдать | CVE-2025-61926Эксплойта нет | Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secretossf · allstar · CWE-453 | Средняя4,6 | — | 0,4 % | 9 окт. 2025 г. |
14Наблюдать | GHSA-879p-8gw4-mcpwЭксплойта нет | fgr Vulnerable to Insecure Default Variable InitializationPyPI · fgr · CWE-453 | Низкая3,7 | — | — | 15 мар. 2024 г. |
8Наблюдать | CVE-2026-19212Эксплойта нет | WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variableCWE-453 | Низкая2,1 | — | 0,5 % | 7 авг. 2026 г. |
8Наблюдать | CVE-2026-41330Эксплойта нет | OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policyopenclaw · openclaw · CWE-453 | Низкая2,0 | — | 0,2 % | 20 апр. 2026 г. |
- CVE-2026-008240В плане
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %google · android17 июн. 2026 г.
- CVE-2021-2742639Наблюдать
GE UR family insecure default variable initialization
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ge · multilin b30 firmware23 мар. 2022 г.
- CVE-2025-4794539Наблюдать
Donetick Has Weak Default JWT Secret
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %donetick · donetick17 мая 2025 г.
- CVE-2026-9295037Наблюдать
vm2 before 3.11.7 Sandbox Escape via CLI require
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %patriksimek · vm217 сент. 2026 г.
- CVE-2024-2141136Наблюдать
Skype for Consumer Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %skype · skype12 мар. 2024 г.
- CVE-2024-4912032Наблюдать
Windows Remote Desktop Services Remote Code Execution Vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %microsoft · windows server 201211 дек. 2024 г.
- CVE-2022-326232Наблюдать
A flaw was found in Openshift.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %redhat · openshift8 дек. 2022 г.
- CVE-2023-2751631Наблюдать
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %softether · vpn12 окт. 2023 г.
- CVE-2025-4856331Наблюдать
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %google · android4 сент. 2025 г.
- CVE-2024-4125530Наблюдать
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %filestash · filestash31 июл. 2024 г.
- CVE-2024-3991625Наблюдать
NFS server misconfiguration allows file access outside the exported directory
СредняяCVSS 6,4Эксплойта нетEPSS 0 %fogproject · fogproject12 июл. 2024 г.
- CVE-2022-4719721Наблюдать
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %ghost · ghost19 янв. 2023 г.
- CVE-2022-4719421Наблюдать
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %ghost · ghost19 янв. 2023 г.
- CVE-2022-4719521Наблюдать
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %ghost · ghost19 янв. 2023 г.
- CVE-2022-4719621Наблюдать
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %ghost · ghost19 янв. 2023 г.
- CVE-2022-4683119Наблюдать
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project
СредняяCVSS 4,9Эксплойта нетEPSS 0 %jetbrains · teamcity8 дек. 2022 г.
- CVE-2025-6192618Наблюдать
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
СредняяCVSS 4,6Эксплойта нетEPSS 0 %ossf · allstar9 окт. 2025 г.
- GHSA-879p-8gw4-mcpw14Наблюдать
fgr Vulnerable to Insecure Default Variable Initialization
НизкаяCVSS 3,7Эксплойта нетPyPI · fgr15 мар. 2024 г.
- CVE-2026-192128Наблюдать
WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %7 авг. 2026 г.
- CVE-2026-413308Наблюдать
OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
НизкаяCVSS 2,0Эксплойта нетEPSS 0 %openclaw · openclaw20 апр. 2026 г.