The product does not initialize a critical resource.
Volume of CVEs assigned to CWE-909 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
102 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40687CRITICAL In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or err | Apr 30, 2026 | 9.1 | 35 | NO | NO |
CVE-2020-12352MEDIUM Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | Nov 23, 2020 | 6.5 | 30 | NO | YES |
CVE-2018-14647HIGH Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by const | Sep 25, 2018 | 7.5 | 30 | NO | NO |
CVE-2026-43040HIGH In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak
Whe | May 1, 2026 | 7.1 | 27 | NO | NO |
CVE-2021-29980HIGH Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbi | Aug 17, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-25016HIGH In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules | Jan 28, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-10811HIGH strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. | Jun 19, 2018 | 7.5 | 27 | NO | NO |
CVE-2022-29968HIGH An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. | May 2, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-1405HIGH A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a de | Apr 8, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-16932HIGH <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the | Oct 16, 2020 | 7.8 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.