CWE-1188
Insecure Default Initialization of Resource
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 11 of 11- CVE-2026-54359—11 h ago
MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on th
- CVE-2026-44892—EPSS 0%11 h ago
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
maven - CVE-2020-13927Critical· 9.8KEVEXPLOITEPSS 94%14 h ago
Apache Airflow's Experimental API Authentication Bypass
- CVE-2023-27524High· 8.9KEVEXPLOITEPSS 84%14 h ago
Apache Superset Insecure Default Initialization of Resource Vulnerability
- CVE-2025-48927Medium· 5.3KEVEPSS 9%14 h ago
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
- CVE-2022-24706Critical· 9.8KEVEXPLOITEPSS 94%14 h ago
Apache CouchDB Insecure Default Initialization of Resource Vulnerability
- CVE-2023-6448Critical· 9.8KEVEPSS 13%14 h ago
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
- CVE-2026-40994High· 8.2EPSS 0%1 d ago
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept me
- CVE-2026-46517High· 7.8EPSS 0%1 d ago
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. At time of publication, there are no publ
pypi - CVE-2026-24197Medium· 6.5EPSS 0%2 d ago
NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during par
- CVE-2025-27809Medium· 5.4EPSS 0%7 d ago
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.