Threats Tagged 'cwe-1188'
View all threats tagged with 'cwe-1188'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1188'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-16504: CWE-1188: Initialization of a Resource with an Insecure Default in VPS.org Zulip templateCVE-2026-16504 0 The VPS.org one-click Zulip template deploys with insecure default settings including a hardcoded application signing key, a default database password 'zulip', and HTTPS disabled by default. This configuration exposes deployments to critical risks such as unauthorized access and data compromise. The vulnerability is identified as CVE-2026-16504 with a high CVSS score of 9.8, indicating critical severity. No specific affected versions or official patches are currently documented. The vendor advisory does not provide explicit remediation guidance or confirm the availability of a fix. Join the discussion | CVE Database V5 | 07/31/2026, 15:19:42 UTC Added: 07/31/2026, 15:34:06 UTC |
CVE-2026-16503: CWE-1327: Binding to an Unrestricted IP Address in VPS.org Supabase templateCVE-2026-16503 0 The VPS.org one-click Supabase template deploys a PostgreSQL instance that listens on all network interfaces (0.0.0.0:5432) with a default password of "postgres". This configuration exposes the database to remote access without authentication changes and bypasses host firewall protections due to Docker's iptables rules. This vulnerability allows unauthenticated attackers to gain full read and write access to the database, posing a critical security risk. Join the discussion | CVE Database V5 | 07/31/2026, 15:18:33 UTC Added: 07/31/2026, 15:34:06 UTC |
CVE-2026-65881: CWE-1188: Initialization of a Resource with an Insecure Default in joomdle.com Joomdle component for JoomlaCVE-2026-65881 0 Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts. Join the discussion | CVE Database V5 | 07/28/2026, 12:38:21 UTC Added: 07/28/2026, 13:08:00 UTC |
CVE-2026-9680: CWE-1188 Initialization of a resource with an insecure default in Alibaba Alibaba Cloud RDS OpenAPI MCP ServerCVE-2026-9680 0 Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. Join the discussion | CVE Database V5 | 07/28/2026, 09:05:30 UTC Added: 07/28/2026, 09:22:52 UTC |
CVE-2026-55708: CWE-1188: Initialization of a Resource with an Insecure Default in NLnet Labs UnboundCVE-2026-55708 0 In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations. Join the discussion | CVE Database V5 | 07/22/2026, 13:09:30 UTC Added: 07/22/2026, 13:22:42 UTC |
CVE-2026-47393: CWE-306: Missing Authentication for Critical Function in MervinPraison PraisonAICVE-2026-47393 0 CVE-2026-47393 affects MervinPraison's PraisonAI multi-agent system. The vulnerability arises because the code-generator for a Flask API server disables authentication by default, exposing critical endpoints without access control. This allows unauthenticated users to interact with the API, potentially accessing sensitive data and controlling LLM orchestration. Versions prior to 4.6.40 ship with this insecure default. The issue is fixed in version 4.6.40 by enabling authentication via configuration. Join the discussion | CVE Database V5 | 07/21/2026, 15:39:28 UTC Added: 07/21/2026, 15:57:38 UTC |
CVE-2026-62415: CWE-1188: Initialization of a Resource with an Insecure Default in joomdonation.com Membership Pro extension for JoomlaCVE-2026-62415 0 An insecure default configuration vulnerability exists in the Membership Pro extension for Joomla versions prior to 4.6.2. This flaw allows unauthenticated users to upload media assets due to improper initialization of resource permissions. The issue is classified under CWE-1188 and carries a critical severity rating with a CVSS score of 9.1. Join the discussion | CVE Database V5 | 07/21/2026, 09:19:19 UTC Added: 07/21/2026, 10:12:30 UTC |
CVE-2026-60024: CWE-1188: Initialization of a Resource with an Insecure Default in joomdonation.com Events Booking extension for JoomlaCVE-2026-60024 0 Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. Join the discussion | CVE Database V5 | 07/17/2026, 15:47:09 UTC Added: 07/18/2026, 11:08:55 UTC |
Showing 1 to 8 of 8 results