Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelbl
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke
Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allo
UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel
An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Cor
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on net
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Event
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-gene
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to exec
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the syst
rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit
OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled'
Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFor
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membe
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces
AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, B
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Do
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption k
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di
WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-c
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does no
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc
OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows privat
Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access r
Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur
AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor
Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by
Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientT
Frequently Asked Questions
What is CWE-1188?
CWE-1188 (CWE-1188) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1188?
There are 94 CVE records associated with CWE-1188 in our database. Of these, 27 are critical severity, 34 are high severity, and 19 are medium severity.
How can I protect against CWE-1188 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1188 using AI-powered security agents.
Detect CWE-1188 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1188 vulnerabilities across your infrastructure.
Get Started