Skip to content
Noroxi

CWE-15 · 83 records

External Control of System or Configuration Setting

CVEs in this class

85 records

  • An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505.

    CriticalCVSS 9.1No exploitEPSS 34%

    wavlink · wl-wn533a8 firmwareJan 14, 2025

  • php-svg-lib unsafe attributes merge when parsing `use` tag

    CriticalCVSS 9.8No exploitEPSS 24%

    dompdf · php-svg-libDec 12, 2023

  • An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505

    CriticalCVSS 9.1No exploitEPSS 19%

    wavlink · wl-wn533a8 firmwareJan 14, 2025

  • Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode

    CriticalCVSS 10.0WeaponizedEPSS 1%

    hahwul · dalfoxMay 27, 2026

  • An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable

    CriticalCVSS 10.0No exploitEPSS 1%

    mistralai · mistral-vibeSep 11, 2026

  • Service Control vulnerabilities allow access to service restart requests and vm configuration settings.

    HighCVSS 8.8No exploitEPSS 13%

    abb · aspect-ent-12 firmwareDec 5, 2024

  • CVE-2024-4326
    39Monitor

    Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui

    CriticalCVSS 9.8No exploitEPSS 1%

    lollms · lollms web uiMay 16, 2024

  • OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace.

    CriticalCVSS 9.8No exploitEPSS 0%

    openai · codex desktopSep 1, 2026

  • An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505.

    CriticalCVSS 9.1No exploitEPSS 2%

    wavlink · wl-wn533a8 firmwareJan 14, 2025

  • Authenticated Remote Code Execution via File Overwrite

    CriticalCVSS 9.4No exploitEPSS 0%

    haxtheweb · haxcms-nodejsJun 5, 2026

  • PostgreSQL PL/Perl environment variable changes execute arbitrary code

    HighCVSS 8.8No exploitEPSS 4%

    postgresql · postgresqlNov 14, 2024

  • Some API functions allow interaction with the registry, which includes reading values as well as data modification.

    CriticalCVSS 9.1No exploitEPSS 1%

    auvesy · versiondogOct 22, 2021

  • Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig

    CriticalCVSS 9.1No exploitEPSS 0%

    legcord · legcord3 days ago

  • Overwrite of builtin Cody commands facilitates RCE

    HighCVSS 8.8No exploitEPSS 1%

    sourcegraph · codyOct 31, 2023

  • Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter pa

    HighCVSS 8.8No exploitEPSS 1%

    teltonika-networks · rut200 firmwareMay 22, 2023

  • PerFact OpenVPN-Client

    HighCVSS 8.8No exploitEPSS 1%

    perfact · openvpn-clientOct 14, 2022

  • Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection

    HighCVSS 8.8No exploitEPSS 0%

    wftpserver · wing ftp serverJul 10, 2025

  • CVE-2023-3321
    35Monitor

    Code Execution through Writable Mosquitto Configuration File

    HighCVSS 8.8No exploitEPSS 0%

    abb · zenonJul 24, 2023

  • Information Disclosure

    HighCVSS 8.8No exploitEPSS 0%

    abb · aspect-ent-12 firmwareDec 5, 2024

  • CVE-2026-1784
    35Monitor

    Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection

    HighCVSS 8.8No exploitEPSS 0%

    redhat · openshift container platformJun 2, 2026

  • Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks

    HighCVSS 8.8No exploitEPSS 0%

    pi-hole · pi-holeMay 11, 2026

  • FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup

    HighCVSS 8.6No exploitEPSS 1%

    freepbx · frameworkAug 13, 2026

  • OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend

    HighCVSS 8.5No exploitEPSS 0%

    openclaw · openclawApr 28, 2026

  • OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env File

    HighCVSS 8.5No exploitEPSS 0%

    openclaw · openclawApr 20, 2026

  • Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

    HighCVSS 8.6No exploitEPSS 0%

    autodesk · fusionSep 10, 2026

All vulnerability classes