İçeriğe atla
Noroxi

CWE-1188 · 261 kayıt

Initialization of a Resource with an Insecure Default

Bu sınıftaki CVE’ler

263 kayıt

  • Apache Superset: Session validation vulnerability when using provided default SECRET_KEY

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    apache · superset24 Nis 2023

  • Remote Code Execution Vulnerability in Packaging

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93

    apache · couchdb26 Nis 2022

  • CVE-2023-6448
    70Bu hafta

    Unitronics VisiLogic uses a default administrative password

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %2

    unitronics · vision1210 firmware5 Ara 2023

  • CVE-2020-11532
    62Bu hafta

    Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server.

    KritikCVSS 9,8SilahlaştırılmışEPSS %77

    zohocorp · manageengine adaudit plus8 May 2020

  • CVE-2025-48927
    54Planlayın

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploit

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %11

    smarsh · telemessage28 May 2025

  • CVE-2020-14011
    48Planlayın

    Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in

    KritikCVSS 9,8Kavram kanıtıEPSS %29

    lansweeper · lansweeper15 Haz 2020

  • CVE-2024-2758
    47Planlayın

    Tempesta FW rate limits are not enabled by default.

    OrtaCVSS 6,3İstismar yokEPSS %73

    tempesta · tempesta fw3 Nis 2024

  • CVE-2018-8014
    45Planlayın

    The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.8

    KritikCVSS 9,8İstismar yokEPSS %21

    apache · tomcat16 May 2018

  • CVE-2021-38759
    44Planlayın

    Raspberry Pi OS through 5.10 has the raspberry default password for the pi account.

    KritikCVSS 9,8Kavram kanıtıEPSS %16

    raspberrypi · raspberry pi os lite7 Ara 2021

  • CVE-2017-5178
    43Planlayın

    An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and p

    KritikCVSS 9,8İstismar yokEPSS %14

    schneider-electric · tableau desktop8 Mar 2017

  • CVE-2021-35336
    42Planlayın

    Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control.

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    tieline · ip audtio gateway firmware1 Tem 2021

  • CVE-2019-5367
    41Planlayın

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    KritikCVSS 9,8İstismar yokEPSS %8

    hp · intelligent management center5 Haz 2019

  • CVE-2017-12739
    41Planlayın

    An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi0

    KritikCVSS 9,8İstismar yokEPSS %6

    siemens · sm-2556 firmware15 Kas 2017

  • CVE-2017-7964
    41Planlayın

    Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to

    KritikCVSS 10,0İstismar yokEPSS %2

    zyxel · wre6505 firmware19 Nis 2017

  • CVE-2019-7252
    40Planlayın

    Linear eMerge E3-Series devices have Default Credentials.

    KritikCVSS 9,8İstismar yokEPSS %5

    nortekcontrol · linear emerge essential firmware2 Tem 2019

  • CVE-2018-15350
    40Planlayın

    Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the rou

    KritikCVSS 9,8İstismar yokEPSS %5

    kraftway · 24f2xg router firmware17 Ağu 2018

  • CVE-2018-19275
    40Planlayın

    The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote

    KritikCVSS 9,8İstismar yokEPSS %5

    mitel · cmg suite2 Nis 2019

  • CVE-2014-0234
    40Planlayın

    The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which

    KritikCVSS 9,8İstismar yokEPSS %4

    redhat · openshift11 Şub 2020

  • CVE-2019-5490
    40Planlayın

    Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled

    KritikCVSS 9,8İstismar yokEPSS %3

    netapp · service processor21 Mar 2019

  • CVE-2019-14222
    40Planlayın

    An issue was discovered in Alfresco Community Edition versions 6.0 and lower.

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    alfresco · alfresco5 Eyl 2019

  • CVE-2020-4001
    40Planlayın

    The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack.

    KritikCVSS 9,8İstismar yokEPSS %3

    vmware · sd-wan orchestrator24 Kas 2020

  • CVE-2019-5497
    40Planlayın

    NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that co

    KritikCVSS 9,8İstismar yokEPSS %3

    netapp · aff a700s firmware1 Tem 2019

  • CVE-2018-5770
    40Planlayın

    An issue was discovered on Tenda AC15 devices.

    KritikCVSS 9,8İstismar yokEPSS %3

    tendacn · ac15 firmware20 Mar 2018

  • CVE-2020-27555
    40Planlayın

    Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrar

    KritikCVSS 9,8İstismar yokEPSS %3

    basetech · ge-131 bt-1837836 firmware17 Kas 2020

  • CVE-2019-11618
    40Planlayın

    doorGets 7.0 has a default administrator credential vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %2

    doorgets · doorgets cms30 Nis 2019

Tüm zafiyet sınıfları