CWE-453 · 20 kayıt
Insecure Default Variable Initialization
Bu sınıftaki CVE’ler
20 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-0082İstismar yok | In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure defaultgoogle · android · CWE-453 | Kritik10,0 | — | %0,2 | 17 Haz 2026 |
39İzleyin | CVE-2021-27426İstismar yok | GE UR family insecure default variable initializationge · multilin b30 firmware · CWE-453 | Kritik9,8 | — | %1,2 | 23 Mar 2022 |
39İzleyin | CVE-2025-47945İstismar yok | Donetick Has Weak Default JWT Secretdonetick · donetick · CWE-453 | Kritik9,8 | — | %0,7 | 17 May 2025 |
37İzleyin | CVE-2026-92950İstismar yok | vm2 before 3.11.7 Sandbox Escape via CLI requirepatriksimek · vm2 · CWE-453 | Kritik9,3 | — | %0,2 | 17 Eyl 2026 |
36İzleyin | CVE-2024-21411İstismar yok | Skype for Consumer Remote Code Execution Vulnerabilityskype · skype · CWE-453 | Yüksek8,8 | — | %2,6 | 12 Mar 2024 |
32İzleyin | CVE-2024-49120İstismar yok | Windows Remote Desktop Services Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-453 | Yüksek8,1 | — | %1,1 | 11 Ara 2024 |
32İzleyin | CVE-2022-3262İstismar yok | A flaw was found in Openshift.redhat · openshift · CWE-453 | Yüksek8,1 | — | %0,7 | 8 Ara 2022 |
31İzleyin | CVE-2023-27516İstismar yok | An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.softether · vpn · CWE-453 | Yüksek7,8 | — | %0,5 | 12 Eki 2023 |
31İzleyin | CVE-2025-48563İstismar yok | In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.google · android · CWE-453 | Yüksek7,8 | — | %0,1 | 4 Eyl 2025 |
30İzleyin | CVE-2024-41255İstismar yok | filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a manfilestash · filestash · CWE-453 | Yüksek7,5 | — | %0,3 | 31 Tem 2024 |
25İzleyin | CVE-2024-39916İstismar yok | NFS server misconfiguration allows file access outside the exported directoryfogproject · fogproject · CWE-453 | Orta6,4 | — | %0,3 | 12 Tem 2024 |
21İzleyin | CVE-2022-47197İstismar yok | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Orta5,4 | — | %1,0 | 19 Oca 2023 |
21İzleyin | CVE-2022-47194İstismar yok | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Orta5,4 | — | %0,8 | 19 Oca 2023 |
21İzleyin | CVE-2022-47195İstismar yok | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Orta5,4 | — | %0,7 | 19 Oca 2023 |
21İzleyin | CVE-2022-47196İstismar yok | An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.ghost · ghost · CWE-453 | Orta5,4 | — | %0,7 | 19 Oca 2023 |
19İzleyin | CVE-2022-46831İstismar yok | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity projectjetbrains · teamcity · CWE-453 | Orta4,9 | — | %0,5 | 8 Ara 2022 |
18İzleyin | CVE-2025-61926İstismar yok | Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secretossf · allstar · CWE-453 | Orta4,6 | — | %0,4 | 9 Eki 2025 |
14İzleyin | GHSA-879p-8gw4-mcpwİstismar yok | fgr Vulnerable to Insecure Default Variable InitializationPyPI · fgr · CWE-453 | Düşük3,7 | — | — | 15 Mar 2024 |
8İzleyin | CVE-2026-19212İstismar yok | WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variableCWE-453 | Düşük2,1 | — | %0,5 | 7 Ağu 2026 |
8İzleyin | CVE-2026-41330İstismar yok | OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policyopenclaw · openclaw · CWE-453 | Düşük2,0 | — | %0,2 | 20 Nis 2026 |
- CVE-2026-008240Planlayın
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default
KritikCVSS 10,0İstismar yokEPSS %0google · android17 Haz 2026
- CVE-2021-2742639İzleyin
GE UR family insecure default variable initialization
KritikCVSS 9,8İstismar yokEPSS %1ge · multilin b30 firmware23 Mar 2022
- CVE-2025-4794539İzleyin
Donetick Has Weak Default JWT Secret
KritikCVSS 9,8İstismar yokEPSS %1donetick · donetick17 May 2025
- CVE-2026-9295037İzleyin
vm2 before 3.11.7 Sandbox Escape via CLI require
KritikCVSS 9,3İstismar yokEPSS %0patriksimek · vm217 Eyl 2026
- CVE-2024-2141136İzleyin
Skype for Consumer Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %3skype · skype12 Mar 2024
- CVE-2024-4912032İzleyin
Windows Remote Desktop Services Remote Code Execution Vulnerability
YüksekCVSS 8,1İstismar yokEPSS %1microsoft · windows server 201211 Ara 2024
- CVE-2022-326232İzleyin
A flaw was found in Openshift.
YüksekCVSS 8,1İstismar yokEPSS %1redhat · openshift8 Ara 2022
- CVE-2023-2751631İzleyin
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.
YüksekCVSS 7,8İstismar yokEPSS %1softether · vpn12 Eki 2023
- CVE-2025-4856331İzleyin
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.
YüksekCVSS 7,8İstismar yokEPSS %0google · android4 Eyl 2025
- CVE-2024-4125530İzleyin
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man
YüksekCVSS 7,5İstismar yokEPSS %0filestash · filestash31 Tem 2024
- CVE-2024-3991625İzleyin
NFS server misconfiguration allows file access outside the exported directory
OrtaCVSS 6,4İstismar yokEPSS %0fogproject · fogproject12 Tem 2024
- CVE-2022-4719721İzleyin
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
OrtaCVSS 5,4İstismar yokEPSS %1ghost · ghost19 Oca 2023
- CVE-2022-4719421İzleyin
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
OrtaCVSS 5,4İstismar yokEPSS %1ghost · ghost19 Oca 2023
- CVE-2022-4719521İzleyin
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
OrtaCVSS 5,4İstismar yokEPSS %1ghost · ghost19 Oca 2023
- CVE-2022-4719621İzleyin
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
OrtaCVSS 5,4İstismar yokEPSS %1ghost · ghost19 Oca 2023
- CVE-2022-4683119İzleyin
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project
OrtaCVSS 4,9İstismar yokEPSS %0jetbrains · teamcity8 Ara 2022
- CVE-2025-6192618İzleyin
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
OrtaCVSS 4,6İstismar yokEPSS %0ossf · allstar9 Eki 2025
- GHSA-879p-8gw4-mcpw14İzleyin
fgr Vulnerable to Insecure Default Variable Initialization
DüşükCVSS 3,7İstismar yokPyPI · fgr15 Mar 2024
- CVE-2026-192128İzleyin
WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
DüşükCVSS 2,1İstismar yokEPSS %07 Ağu 2026
- CVE-2026-413308İzleyin
OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
DüşükCVSS 2,0İstismar yokEPSS %0openclaw · openclaw20 Nis 2026