CWE-665: Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
122 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-87616 — Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had
- CVE-2025-55118 — BMC Control-M/Agent memory corruption in SSL/TLS communication
- CVE-2026-0940 — A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr
- CVE-2024-0089 — CVE
- CVE-2026-54409 — A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulne
- CVE-2026-78940 — Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi
- CVE-2025-21100 — Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged use
- CVE-2026-54777 — CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
- CVE-2026-12233 — Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention
- CVE-2026-20734 — Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R
- CVE-2025-35991 — Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat
- CVE-2024-26021 — Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged
- CVE-2026-44434 — Quicly is vulnerable to stateless reset injection
- CVE-2025-12902 — Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces
- CVE-2026-12539 — Docker Sandboxes ICMP egress restriction bypass after daemon restart
- CVE-2025-22834 — ThirdPartyVideo SetVariable Vulnerability
- CVE-2026-34553 — iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()
- CVE-2025-25058 — Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es
- CVE-2025-24511 — Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may
- CVE-2024-36331 — Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN
Recently published
- CVE-2026-87616 — Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had
- CVE-2026-78940 — Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi
- CVE-2026-12233 — Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention
- CVE-2026-20734 — Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R
- CVE-2026-44434 — Quicly is vulnerable to stateless reset injection
- CVE-2026-54777 — CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
- CVE-2026-54409 — A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulne
- CVE-2026-54279 — AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
- CVE-2026-12539 — Docker Sandboxes ICMP egress restriction bypass after daemon restart
- CVE-2025-35991 — Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat
- CVE-2026-34553 — iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()
- CVE-2026-0940 — A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr
- CVE-2026-26958 — filippo.io/edwards25519 MultiScalarMult function produces invalid results or undefined behavior if receiver is not the identity
- CVE-2025-48509 — Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause m
- CVE-2025-25058 — Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (es
- CVE-2025-12902 — Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces
- CVE-2025-55118 — BMC Control-M/Agent memory corruption in SSL/TLS communication
- CVE-2024-36331 — Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN
- CVE-2025-24511 — Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may
- CVE-2025-22834 — ThirdPartyVideo SetVariable Vulnerability