VulnSea

CWE-1392

CVEs classified under CWE-1392, newest first.

12 CVEsRSS

CVE-2026-90940Medium· 5.3PoC
1w ago

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

Twilight201206030 · novel-plusEPSS 0.31%via NVD
CVE-2026-90498High· 7.3PoC
1w ago

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT

A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The …

Midnightlenve · vhrEPSS 0.28%via NVD
CVE-2026-90456Critical· 9.2
1w ago

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the s…

MidnightCISA · MalcolmEPSS 0.25%via NVD
CVE-2026-90451High· 8.2
1w ago

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration w…

TwilightCISA · MalcolmEPSS 0.33%via NVD
CVE-2026-78573Critical· 9.8
1w ago

IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

Midnightibm · contextforgeEPSS 0.39%via NVD
CVE-2026-86464Critical· 9.9
1w ago

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

MidnightEclipse Foundation · Eclipse aeriOSEPSS 0.35%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

Twilightgeolens · geolensvia GHSA
CVE-2026-68503Critical· 9.8PoC
1mo ago

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc…

Abyssalgrisuno · LazyOwnEPSS 0.50%via NVD
GHSA-f25v-x6vr-962gCritical· 10.0
1mo ago

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Midnightpheditor · pheditor/pheditorvia GHSA
CVE-2026-46386Critical· 9.9
2mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :m…

MidnightEPSS 0.49%via NVD
CVE-2026-31837High· 7.5
6mo ago

Istio is an open platform to connect, manage, and secure microservices

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless …

Twilightistio · istioEPSS 0.38%via NVD
CVE-2025-9577Low· 2.5
1y ago

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credenti…

Sunlittotolink · x2000r_firmwareEPSS 0.21%via NVD
CWE-1392 vulnerabilities (CVEs) · VulnSea