CWE-1188
307 CVEs • Abstraction: Base
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CVEs (307)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been chang...Show more |
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings...Show more |
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User...Show more |
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings. |
1Gemteks 2Wrtm 127acn Firmware Wrtm 127x9 FirmwareJun 17, 2026 Sep 24, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Co...Show more |
In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: Android...Show more |
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no a...Show more |
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverabilit...Show more |
<p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript c...Show more |
3Canonical DebianGruntjs3Debian Linux GruntUbuntu LinuxJun 17, 2026 Sep 3, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users...Show more |
4Aliasrobotics Enabled RoboticsMobile Industrial Robotics+1 more10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreJun 17, 2026 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way fo...Show more |
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Pack...Show more |
1Zohocorp 2Manageengine Adaudit Plus Manageengine Datasecurity PlusJun 17, 2026 May 8, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations...Show more |
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicio...Show more |
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic Authentication or an a...Show more |
1Netapp 3All Flash Fabric Attached Storage A400 Firmware Fabric Attached Storage 8300 FirmwareFabric Attached Storage 8700 FirmwareJun 17, 2026 Feb 26, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via loc...Show more |
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within th...Show more |
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related...Show more |
1Dten 2D5 Firmware D7 FirmwareJun 17, 2026 Jan 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement. |