The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
Volume of CVEs assigned to CWE-1188 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
308 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27524CRITICAL Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation in | Apr 24, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-24706CRITICAL In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has | Apr 26, 2022 | 9.8 | 99 | YES | YES |
CVE-2020-13927CRITICAL The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Ai | Nov 10, 2020 | 9.8 | 99 | YES | YES |
CVE-2020-11532CRITICAL Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication fo | May 8, 2020 | 9.8 | 76 | NO | YES |
CVE-2023-6448CRITICAL Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take | Dec 5, 2023 | 9.8 | 71 | YES | NO |
CVE-2026-44338HIGH PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that s | May 8, 2026 | 7.3 | 63 | NO | YES |
CVE-2025-48927MEDIUM The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025. | May 28, 2025 | 5.3 | 62 | YES | NO |
CVE-2020-14011CRITICAL Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allow | Jun 15, 2020 | 9.8 | 52 | NO | YES |
CVE-2018-16752HIGH LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication | Sep 20, 2018 | 8.8 | 52 | NO | NO |
CVE-2021-38759CRITICAL Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges. | Dec 7, 2021 | 9.8 | 50 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.