Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-453

Insecure Default Variable Initialization

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

18
Assigned CVEs
349th
Commonality Rank
7.1
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-453 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2022
4 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27426CRITICAL
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factor
Mar 23, 20229.831NONO
CVE-2026-0082HIGH
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalat
Jun 17, 20267.829NONO
CVE-2025-47945CRITICAL
Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak
May 17, 20259.827NONO
CVE-2025-30206CRITICAL
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration,
Apr 15, 20259.827NONO
CVE-2024-21411HIGH
Skype for Consumer Remote Code Execution Vulnerability
Mar 12, 20248.827NONO
CVE-2022-3262HIGH
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an
Dec 8, 20228.126NONO
CVE-2025-48563HIGH
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with n
Sep 4, 20257.825NONO
CVE-2023-27516HIGH
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to una
Oct 12, 20237.823NONO
CVE-2024-49120HIGH
Windows Remote Desktop Services Remote Code Execution Vulnerability
Dec 12, 20248.122NONO
CVE-2024-41255HIGH
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init funct
Jul 31, 20247.522NONO
View all 18 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
17%
10%
4.0-4.9
22%
19%
5.0-5.9
16%
6.0-6.9
22%
26%
7.0-7.9
17%
11%
8.0-8.9
17%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products