İçeriğe atla
Noroxi

CWE-453 · 20 kayıt

Insecure Default Variable Initialization

Bu sınıftaki CVE’ler

20 kayıt

  • CVE-2026-0082
    40Planlayın

    In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default

    KritikCVSS 10,0İstismar yokEPSS %0

    google · android17 Haz 2026

  • CVE-2021-27426
    39İzleyin

    GE UR family insecure default variable initialization

    KritikCVSS 9,8İstismar yokEPSS %1

    ge · multilin b30 firmware23 Mar 2022

  • CVE-2025-47945
    39İzleyin

    Donetick Has Weak Default JWT Secret

    KritikCVSS 9,8İstismar yokEPSS %1

    donetick · donetick17 May 2025

  • CVE-2026-92950
    37İzleyin

    vm2 before 3.11.7 Sandbox Escape via CLI require

    KritikCVSS 9,3İstismar yokEPSS %0

    patriksimek · vm217 Eyl 2026

  • CVE-2024-21411
    36İzleyin

    Skype for Consumer Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %3

    skype · skype12 Mar 2024

  • CVE-2024-49120
    32İzleyin

    Windows Remote Desktop Services Remote Code Execution Vulnerability

    YüksekCVSS 8,1İstismar yokEPSS %1

    microsoft · windows server 201211 Ara 2024

  • CVE-2022-3262
    32İzleyin

    A flaw was found in Openshift.

    YüksekCVSS 8,1İstismar yokEPSS %1

    redhat · openshift8 Ara 2022

  • CVE-2023-27516
    31İzleyin

    An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.

    YüksekCVSS 7,8İstismar yokEPSS %1

    softether · vpn12 Eki 2023

  • CVE-2025-48563
    31İzleyin

    In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value.

    YüksekCVSS 7,8İstismar yokEPSS %0

    google · android4 Eyl 2025

  • CVE-2024-41255
    30İzleyin

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man

    YüksekCVSS 7,5İstismar yokEPSS %0

    filestash · filestash31 Tem 2024

  • CVE-2024-39916
    25İzleyin

    NFS server misconfiguration allows file access outside the exported directory

    OrtaCVSS 6,4İstismar yokEPSS %0

    fogproject · fogproject12 Tem 2024

  • CVE-2022-47197
    21İzleyin

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    OrtaCVSS 5,4İstismar yokEPSS %1

    ghost · ghost19 Oca 2023

  • CVE-2022-47194
    21İzleyin

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    OrtaCVSS 5,4İstismar yokEPSS %1

    ghost · ghost19 Oca 2023

  • CVE-2022-47195
    21İzleyin

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    OrtaCVSS 5,4İstismar yokEPSS %1

    ghost · ghost19 Oca 2023

  • CVE-2022-47196
    21İzleyin

    An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.

    OrtaCVSS 5,4İstismar yokEPSS %1

    ghost · ghost19 Oca 2023

  • CVE-2022-46831
    19İzleyin

    In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project

    OrtaCVSS 4,9İstismar yokEPSS %0

    jetbrains · teamcity8 Ara 2022

  • CVE-2025-61926
    18İzleyin

    Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret

    OrtaCVSS 4,6İstismar yokEPSS %0

    ossf · allstar9 Eki 2025

  • fgr Vulnerable to Insecure Default Variable Initialization

    DüşükCVSS 3,7İstismar yok

    PyPI · fgr15 Mar 2024

  • WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable

    DüşükCVSS 2,1İstismar yokEPSS %0

    7 Ağu 2026

  • OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy

    DüşükCVSS 2,0İstismar yokEPSS %0

    openclaw · openclaw20 Nis 2026

Tüm zafiyet sınıfları