CWE-453: Insecure Default Variable Initialization
The product, by default, initializes an internal variable with an insecure or less secure value than is possible.
16 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-30206 — Dpanel's hard-coded JWT secret leads to remote code execution
- CVE-2025-47945 — Donetick Has Weak Default JWT Secret
- CVE-2024-39916 — NFS server misconfiguration allows file access outside the exported directory
- CVE-2025-61926 — Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
- CVE-2026-19212 — WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
- CVE-2026-41330 — OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
Recently published
- CVE-2026-19212 — WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
- CVE-2026-41330 — OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy
- CVE-2025-61926 — Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
- CVE-2025-47945 — Donetick Has Weak Default JWT Secret
- CVE-2025-30206 — Dpanel's hard-coded JWT secret leads to remote code execution
- CVE-2024-39916 — NFS server misconfiguration allows file access outside the exported directory