The product, by default, initializes an internal variable with an insecure or less secure value than is possible.
Volume of CVEs assigned to CWE-453 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27426CRITICAL GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factor | Mar 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-0082HIGH In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalat | Jun 17, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-47945CRITICAL Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak | May 17, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-30206CRITICAL Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, | Apr 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-21411HIGH Skype for Consumer Remote Code Execution Vulnerability | Mar 12, 2024 | 8.8 | 27 | NO | NO |
CVE-2022-3262HIGH A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an | Dec 8, 2022 | 8.1 | 26 | NO | NO |
CVE-2025-48563HIGH In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with n | Sep 4, 2025 | 7.8 | 25 | NO | NO |
CVE-2023-27516HIGH An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to una | Oct 12, 2023 | 7.8 | 23 | NO | NO |
CVE-2024-49120HIGH Windows Remote Desktop Services Remote Code Execution Vulnerability | Dec 12, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-41255HIGH filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init funct | Jul 31, 2024 | 7.5 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.