CWE-1188 · 261 kayıt
Initialization of a Resource with an Insecure Default
Bu sınıftaki CVE’ler
263 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2023-27524Silahlaştırılmış | Apache Superset: Session validation vulnerability when using provided default SECRET_KEYapache · superset · CWE-1188 | Kritik9,8 | KEV | %97,4 | 24 Nis 2023 |
97Hemen | CVE-2022-24706Silahlaştırılmış | Remote Code Execution Vulnerability in Packagingapache · couchdb · CWE-1188 | Kritik9,8 | KEV | %92,5 | 26 Nis 2022 |
70Bu hafta | CVE-2023-6448Silahlaştırılmış | Unitronics VisiLogic uses a default administrative passwordunitronics · vision1210 firmware · CWE-1188 | Kritik9,8 | KEV | %2,1 | 5 Ara 2023 |
62Bu hafta | CVE-2020-11532Silahlaştırılmış | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.zohocorp · manageengine adaudit plus · CWE-1188 | Kritik9,8 | — | %77,5 | 8 May 2020 |
54Planlayın | CVE-2025-48927Silahlaştırılmış | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploitsmarsh · telemessage · CWE-1188 | Orta5,3 | KEV | %11,1 | 28 May 2025 |
48Planlayın | CVE-2020-14011Kavram kanıtı | Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in lansweeper · lansweeper · CWE-1188 | Kritik9,8 | — | %29,5 | 15 Haz 2020 |
47Planlayın | CVE-2024-2758İstismar yok | Tempesta FW rate limits are not enabled by default.tempesta · tempesta fw · CWE-1188 | Orta6,3 | — | %72,8 | 3 Nis 2024 |
45Planlayın | CVE-2018-8014İstismar yok | The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8apache · tomcat · CWE-1188 | Kritik9,8 | — | %21,3 | 16 May 2018 |
44Planlayın | CVE-2021-38759Kavram kanıtı | Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.raspberrypi · raspberry pi os lite · CWE-1188 | Kritik9,8 | — | %15,7 | 7 Ara 2021 |
43Planlayın | CVE-2017-5178İstismar yok | An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and pschneider-electric · tableau desktop · CWE-1188 | Kritik9,8 | — | %13,6 | 8 Mar 2017 |
42Planlayın | CVE-2021-35336Kavram kanıtı | Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.tieline · ip audtio gateway firmware · CWE-1188 | Kritik9,8 | — | %10,1 | 1 Tem 2021 |
41Planlayın | CVE-2019-5367İstismar yok | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-1188 | Kritik9,8 | — | %8,0 | 5 Haz 2019 |
41Planlayın | CVE-2017-12739İstismar yok | An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi0siemens · sm-2556 firmware · CWE-1188 | Kritik9,8 | — | %5,6 | 15 Kas 2017 |
41Planlayın | CVE-2017-7964İstismar yok | Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to zyxel · wre6505 firmware · CWE-1188 | Kritik10,0 | — | %2,5 | 19 Nis 2017 |
40Planlayın | CVE-2019-7252İstismar yok | Linear eMerge E3-Series devices have Default Credentials.nortekcontrol · linear emerge essential firmware · CWE-1188 | Kritik9,8 | — | %4,9 | 2 Tem 2019 |
40Planlayın | CVE-2018-15350İstismar yok | Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the roukraftway · 24f2xg router firmware · CWE-1188 | Kritik9,8 | — | %4,7 | 17 Ağu 2018 |
40Planlayın | CVE-2018-19275İstismar yok | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remotemitel · cmg suite · CWE-1188 | Kritik9,8 | — | %4,6 | 2 Nis 2019 |
40Planlayın | CVE-2014-0234İstismar yok | The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which redhat · openshift · CWE-1188 | Kritik9,8 | — | %3,8 | 11 Şub 2020 |
40Planlayın | CVE-2019-5490İstismar yok | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enablednetapp · service processor · CWE-1188 | Kritik9,8 | — | %3,5 | 21 Mar 2019 |
40Planlayın | CVE-2019-14222Kavram kanıtı | An issue was discovered in Alfresco Community Edition versions 6.0 and lower.alfresco · alfresco · CWE-1188 | Kritik9,8 | — | %2,9 | 5 Eyl 2019 |
40Planlayın | CVE-2020-4001İstismar yok | The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.vmware · sd-wan orchestrator · CWE-1188 | Kritik9,8 | — | %2,9 | 24 Kas 2020 |
40Planlayın | CVE-2019-5497İstismar yok | NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that conetapp · aff a700s firmware · CWE-1188 | Kritik9,8 | — | %2,9 | 1 Tem 2019 |
40Planlayın | CVE-2018-5770İstismar yok | An issue was discovered on Tenda AC15 devices.tendacn · ac15 firmware · CWE-1188 | Kritik9,8 | — | %2,7 | 20 Mar 2018 |
40Planlayın | CVE-2020-27555İstismar yok | Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrarbasetech · ge-131 bt-1837836 firmware · CWE-1188 | Kritik9,8 | — | %2,5 | 17 Kas 2020 |
40Planlayın | CVE-2019-11618İstismar yok | doorGets 7.0 has a default administrator credential vulnerability.doorgets · doorgets cms · CWE-1188 | Kritik9,8 | — | %2,3 | 30 Nis 2019 |
- CVE-2023-2752498Hemen
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97apache · superset24 Nis 2023
- CVE-2022-2470697Hemen
Remote Code Execution Vulnerability in Packaging
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93apache · couchdb26 Nis 2022
- CVE-2023-644870Bu hafta
Unitronics VisiLogic uses a default administrative password
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %2unitronics · vision1210 firmware5 Ara 2023
- CVE-2020-1153262Bu hafta
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.
KritikCVSS 9,8SilahlaştırılmışEPSS %77zohocorp · manageengine adaudit plus8 May 2020
- CVE-2025-4892754Planlayın
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %11smarsh · telemessage28 May 2025
- CVE-2020-1401148Planlayın
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in
KritikCVSS 9,8Kavram kanıtıEPSS %29lansweeper · lansweeper15 Haz 2020
- CVE-2024-275847Planlayın
Tempesta FW rate limits are not enabled by default.
OrtaCVSS 6,3İstismar yokEPSS %73tempesta · tempesta fw3 Nis 2024
- CVE-2018-801445Planlayın
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8
KritikCVSS 9,8İstismar yokEPSS %21apache · tomcat16 May 2018
- CVE-2021-3875944Planlayın
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.
KritikCVSS 9,8Kavram kanıtıEPSS %16raspberrypi · raspberry pi os lite7 Ara 2021
- CVE-2017-517843Planlayın
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and p
KritikCVSS 9,8İstismar yokEPSS %14schneider-electric · tableau desktop8 Mar 2017
- CVE-2021-3533642Planlayın
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.
KritikCVSS 9,8Kavram kanıtıEPSS %10tieline · ip audtio gateway firmware1 Tem 2021
- CVE-2019-536741Planlayın
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
KritikCVSS 9,8İstismar yokEPSS %8hp · intelligent management center5 Haz 2019
- CVE-2017-1273941Planlayın
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi0
KritikCVSS 9,8İstismar yokEPSS %6siemens · sm-2556 firmware15 Kas 2017
- CVE-2017-796441Planlayın
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to
KritikCVSS 10,0İstismar yokEPSS %2zyxel · wre6505 firmware19 Nis 2017
- CVE-2019-725240Planlayın
Linear eMerge E3-Series devices have Default Credentials.
KritikCVSS 9,8İstismar yokEPSS %5nortekcontrol · linear emerge essential firmware2 Tem 2019
- CVE-2018-1535040Planlayın
Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the rou
KritikCVSS 9,8İstismar yokEPSS %5kraftway · 24f2xg router firmware17 Ağu 2018
- CVE-2018-1927540Planlayın
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote
KritikCVSS 9,8İstismar yokEPSS %5mitel · cmg suite2 Nis 2019
- CVE-2014-023440Planlayın
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which
KritikCVSS 9,8İstismar yokEPSS %4redhat · openshift11 Şub 2020
- CVE-2019-549040Planlayın
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled
KritikCVSS 9,8İstismar yokEPSS %3netapp · service processor21 Mar 2019
- CVE-2019-1422240Planlayın
An issue was discovered in Alfresco Community Edition versions 6.0 and lower.
KritikCVSS 9,8Kavram kanıtıEPSS %3alfresco · alfresco5 Eyl 2019
- CVE-2020-400140Planlayın
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.
KritikCVSS 9,8İstismar yokEPSS %3vmware · sd-wan orchestrator24 Kas 2020
- CVE-2019-549740Planlayın
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that co
KritikCVSS 9,8İstismar yokEPSS %3netapp · aff a700s firmware1 Tem 2019
- CVE-2018-577040Planlayın
An issue was discovered on Tenda AC15 devices.
KritikCVSS 9,8İstismar yokEPSS %3tendacn · ac15 firmware20 Mar 2018
- CVE-2020-2755540Planlayın
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrar
KritikCVSS 9,8İstismar yokEPSS %3basetech · ge-131 bt-1837836 firmware17 Kas 2020
- CVE-2019-1161840Planlayın
doorGets 7.0 has a default administrator credential vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2doorgets · doorgets cms30 Nis 2019