CWE-909: Missing Initialization of Resource
The product does not initialize a critical resource.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8117 — Account Takeover via Reset Password Functionality in PAD CMS
- CVE-2024-53845 — AES/CBC Constant IV Vulnerability in ESPTouch v2
- CVE-2025-54388 — Moby's Firewalld reload makes published container ports accessible from remote hosts
- CVE-2026-40687 — In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-
- CVE-2025-54410 — Moby's Firewalld reload removes bridge network isolation
- CVE-2024-32945 — LaTeX post content manipulation via renderer state leak across contexts
Recently published
- CVE-2026-40687 — In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-
- CVE-2025-8117 — Account Takeover via Reset Password Functionality in PAD CMS
- CVE-2025-54410 — Moby's Firewalld reload removes bridge network isolation
- CVE-2025-54388 — Moby's Firewalld reload makes published container ports accessible from remote hosts
- CVE-2024-53845 — AES/CBC Constant IV Vulnerability in ESPTouch v2
- CVE-2024-32945 — LaTeX post content manipulation via renderer state leak across contexts