Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Trave
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl
PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSC
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose
NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon
A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Serv
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and inclu
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to ex
Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to o
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li
In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles
HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configur
In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic erro
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unboun
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen
The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted network
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / da
A configuration weakness in the device’s remote management service allows an authenticated session to be established ove
MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. W
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python pr
Frequently Asked Questions
What is CWE-1188?
CWE-1188 (CWE-1188) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1188?
There are 94 CVE records associated with CWE-1188 in our database. Of these, 27 are critical severity, 34 are high severity, and 19 are medium severity.
How can I protect against CWE-1188 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1188 using AI-powered security agents.
Detect CWE-1188 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1188 vulnerabilities across your infrastructure.
Get Started