CWE-1188: CWE-1188

64
Total CVEs
22
Critical
21
High
7.9
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
7
2025
29
2024
10
2023
4
2022
4

Top Affected Vendors

1 Google 6
2 Linux 3
3 Apache 2
4 Pangolin 1
5 Vitec 1
6 Liferay 1
7 Tieline 1
8 Antek 1
9 Basetech 1
10 Hashicorp 1

All CWE-1188 CVEs (64)

CVE-2025-29985
6.5

Dell Common Event Enabler version 9.0.0.0 contains an insecure default configuration vulnerability in its Common Anti-Virus Agent component. Unauthent...

Apr 8, 2025
CVE-2025-32330
5.7

This vulnerability allows attackers within Bluetooth range to intercept Auracast audio streams on Android devices due to an insecure default password ...

Sep 4, 2025
CVE-2025-38523
5.5

This CVE is a Linux kernel vulnerability in the CIFS/SMB Direct client code where the smbd_response slab isn't properly marked for usercopy operations...

Aug 16, 2025
CVE-2022-49099
5.5

This CVE addresses a DMA (Direct Memory Access) initialization vulnerability in the Linux kernel's Hyper-V vmbus driver. The issue occurs when device ...

Feb 26, 2025
CVE-2021-47343
5.5

This CVE is an uninitialized variable vulnerability in the Linux kernel's device mapper btree removal function. When removal fails due to an IO read e...

May 21, 2024
CVE-2025-52622
5.4

BigFix SaaS fails to include security headers in HTTP responses, weakening client-side protections. This makes web applications more vulnerable to att...

Dec 2, 2025
CVE-2026-1675
5.3

The Advanced Country Blocker WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to bypass geolocation bl...

Feb 7, 2026
CVE-2025-53602
5.3

Zipkin versions through 3.5.1 expose a /heapdump endpoint via Spring Boot Actuator that can be accessed without authentication. This allows attackers ...

Jul 4, 2025
CVE-2025-48927
KEV 5.3

The TeleMessage service exposes a Spring Boot Actuator heap dump endpoint at /heapdump, allowing attackers to retrieve memory contents. This vulnerabi...

May 28, 2025
CVE-2025-64781
4.7

This vulnerability allows attackers to redirect users to arbitrary malicious websites by exploiting a default configuration in GroupSession products. ...

Dec 12, 2025
CVE-2025-59044
4.4

Himmelblau 0.9.x versions derive numeric GIDs from Entra ID group display names, allowing distinct groups with identical names to map to the same GID....

Sep 9, 2025
CVE-2020-11917
4.3

This vulnerability exposes Siime Eye devices through their default SSID values, allowing attackers to map device locations using public databases like...

Nov 7, 2024
CVE-2025-66414
N/A

This vulnerability allows malicious websites to bypass same-origin policy restrictions via DNS rebinding attacks against local HTTP-based MCP servers ...

Dec 2, 2025
CVE-2025-66416
N/A

The MCP Python SDK prior to version 1.23.0 lacks DNS rebinding protection by default for HTTP-based servers. This allows malicious websites to bypass ...

Dec 2, 2025

About CWE-1188 (CWE-1188)

Our database tracks 64 CVEs classified as CWE-1188, with 22 rated critical and 21 rated high severity. The average CVSS score for CWE-1188 vulnerabilities is 7.9.

External reference: View CWE-1188 on MITRE CWE →

Monitor CWE-1188 Vulnerabilities

Get alerted when new CWE-1188 CVEs affect your infrastructure.

Start Monitoring Free