CWE-1188

CWE-1188 · 5 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-1188, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-86246

    Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects …

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-93354public PoC

    Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is en…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-97055public PoC

    SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deplo…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-89139public PoC

    Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-61793public PoC

    Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fo…

    AI risk analysis on Exploit-DB.ai →