CWE-15 · 83 records
External Control of System or Configuration Setting
CVEs in this class
85 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2024-39280No exploit | An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505.wavlink · wl-wn533a8 firmware · CWE-15 | Critical9.1 | — | 34.2% | Jan 14, 2025 |
46Plan | CVE-2023-50252No exploit | php-svg-lib unsafe attributes merge when parsing `use` tagdompdf · php-svg-lib · CWE-15 | Critical9.8 | — | 23.9% | Dec 12, 2023 |
42Plan | CVE-2024-38666No exploit | An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505wavlink · wl-wn533a8 firmware · CWE-15 | Critical9.1 | — | 18.9% | Jan 14, 2025 |
40Plan | CVE-2026-45087Weaponized | Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Modehahwul · dalfox · CWE-15 | Critical10.0 | — | 1.4% | May 27, 2026 |
40Plan | CVE-2026-87987No exploit | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable mistralai · mistral-vibe · CWE-15 | Critical10.0 | — | 0.6% | Sep 11, 2026 |
39Monitor | CVE-2024-51544No exploit | Service Control vulnerabilities allow access to service restart requests and vm configuration settings.abb · aspect-ent-12 firmware · CWE-15 | High8.8 | — | 13.2% | Dec 5, 2024 |
39Monitor | CVE-2024-4326No exploit | Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webuilollms · lollms web ui · CWE-15 | Critical9.8 | — | 1.0% | May 16, 2024 |
39Monitor | CVE-2026-19593No exploit | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace.openai · codex desktop · CWE-15 | Critical9.8 | — | 0.4% | Sep 1, 2026 |
37Monitor | CVE-2024-39602No exploit | An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505.wavlink · wl-wn533a8 firmware · CWE-15 | Critical9.1 | — | 2.3% | Jan 14, 2025 |
37Monitor | CVE-2026-46399No exploit | Authenticated Remote Code Execution via File Overwritehaxtheweb · haxcms-nodejs · CWE-15 | Critical9.4 | — | 0.5% | Jun 5, 2026 |
36Monitor | CVE-2024-10979No exploit | PostgreSQL PL/Perl environment variable changes execute arbitrary codepostgresql · postgresql · CWE-15 | High8.8 | — | 4.4% | Nov 14, 2024 |
36Monitor | CVE-2021-38453No exploit | Some API functions allow interaction with the registry, which includes reading values as well as data modification.auvesy · versiondog · CWE-15 | Critical9.1 | — | 1.1% | Oct 22, 2021 |
36Monitor | CVE-2026-105294No exploit | Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfiglegcord · legcord · CWE-15 | Critical9.1 | — | 0.2% | 3 days ago |
35Monitor | CVE-2023-46248No exploit | Overwrite of builtin Cody commands facilitates RCEsourcegraph · cody · CWE-15 | High8.8 | — | 1.1% | Oct 31, 2023 |
35Monitor | CVE-2023-32349No exploit | Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter pateltonika-networks · rut200 firmware · CWE-15 | High8.8 | — | 1.1% | May 22, 2023 |
35Monitor | CVE-2021-27406No exploit | PerFact OpenVPN-Clientperfact · openvpn-client · CWE-15 | High8.8 | — | 1.0% | Oct 14, 2022 |
35Monitor | CVE-2025-27889No exploit | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injectionwftpserver · wing ftp server · CWE-15 | High8.8 | — | 0.5% | Jul 10, 2025 |
35Monitor | CVE-2023-3321No exploit | Code Execution through Writable Mosquitto Configuration Fileabb · zenon · CWE-15 | High8.8 | — | 0.4% | Jul 24, 2023 |
35Monitor | CVE-2024-51543No exploit | Information Disclosureabb · aspect-ent-12 firmware · CWE-15 | High8.8 | — | 0.3% | Dec 5, 2024 |
35Monitor | CVE-2026-1784No exploit | Ose-cluster-ingress-operator: remote code execution through haproxy configuration injectionredhat · openshift container platform · CWE-15 | High8.8 | — | 0.2% | Jun 2, 2026 |
35Monitor | CVE-2026-41489No exploit | Pi-hole: Local privilege escalation via config-controlled path in root-executed service hookspi-hole · pi-hole · CWE-15 | High8.8 | — | 0.2% | May 11, 2026 |
34Monitor | CVE-2026-73661No exploit | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backupfreepbx · framework · CWE-15 | High8.6 | — | 0.6% | Aug 13, 2026 |
34Monitor | CVE-2026-41384No exploit | OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backendopenclaw · openclaw · CWE-15 | High8.5 | — | 0.2% | Apr 28, 2026 |
34Monitor | CVE-2026-41294No exploit | OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env Fileopenclaw · openclaw · CWE-15 | High8.5 | — | 0.2% | Apr 20, 2026 |
34Monitor | CVE-2026-85217No exploit | Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktopautodesk · fusion · CWE-15 | High8.6 | — | 0.2% | Sep 10, 2026 |
- CVE-2024-3928046Plan
An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505.
CriticalCVSS 9.1No exploitEPSS 34%wavlink · wl-wn533a8 firmwareJan 14, 2025
- CVE-2023-5025246Plan
php-svg-lib unsafe attributes merge when parsing `use` tag
CriticalCVSS 9.8No exploitEPSS 24%dompdf · php-svg-libDec 12, 2023
- CVE-2024-3866642Plan
An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505
CriticalCVSS 9.1No exploitEPSS 19%wavlink · wl-wn533a8 firmwareJan 14, 2025
- CVE-2026-4508740Plan
Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
CriticalCVSS 10.0WeaponizedEPSS 1%hahwul · dalfoxMay 27, 2026
- CVE-2026-8798740Plan
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable
CriticalCVSS 10.0No exploitEPSS 1%mistralai · mistral-vibeSep 11, 2026
- CVE-2024-5154439Monitor
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
HighCVSS 8.8No exploitEPSS 13%abb · aspect-ent-12 firmwareDec 5, 2024
- CVE-2024-432639Monitor
Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui
CriticalCVSS 9.8No exploitEPSS 1%lollms · lollms web uiMay 16, 2024
- CVE-2026-1959339Monitor
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace.
CriticalCVSS 9.8No exploitEPSS 0%openai · codex desktopSep 1, 2026
- CVE-2024-3960237Monitor
An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505.
CriticalCVSS 9.1No exploitEPSS 2%wavlink · wl-wn533a8 firmwareJan 14, 2025
- CVE-2026-4639937Monitor
Authenticated Remote Code Execution via File Overwrite
CriticalCVSS 9.4No exploitEPSS 0%haxtheweb · haxcms-nodejsJun 5, 2026
- CVE-2024-1097936Monitor
PostgreSQL PL/Perl environment variable changes execute arbitrary code
HighCVSS 8.8No exploitEPSS 4%postgresql · postgresqlNov 14, 2024
- CVE-2021-3845336Monitor
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
CriticalCVSS 9.1No exploitEPSS 1%auvesy · versiondogOct 22, 2021
- CVE-2026-10529436Monitor
Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig
CriticalCVSS 9.1No exploitEPSS 0%legcord · legcord3 days ago
- CVE-2023-4624835Monitor
Overwrite of builtin Cody commands facilitates RCE
HighCVSS 8.8No exploitEPSS 1%sourcegraph · codyOct 31, 2023
- CVE-2023-3234935Monitor
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter pa
HighCVSS 8.8No exploitEPSS 1%teltonika-networks · rut200 firmwareMay 22, 2023
- CVE-2021-2740635Monitor
PerFact OpenVPN-Client
HighCVSS 8.8No exploitEPSS 1%perfact · openvpn-clientOct 14, 2022
- CVE-2025-2788935Monitor
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection
HighCVSS 8.8No exploitEPSS 0%wftpserver · wing ftp serverJul 10, 2025
- CVE-2023-332135Monitor
Code Execution through Writable Mosquitto Configuration File
HighCVSS 8.8No exploitEPSS 0%abb · zenonJul 24, 2023
- CVE-2024-5154335Monitor
Information Disclosure
HighCVSS 8.8No exploitEPSS 0%abb · aspect-ent-12 firmwareDec 5, 2024
- CVE-2026-178435Monitor
Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection
HighCVSS 8.8No exploitEPSS 0%redhat · openshift container platformJun 2, 2026
- CVE-2026-4148935Monitor
Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks
HighCVSS 8.8No exploitEPSS 0%pi-hole · pi-holeMay 11, 2026
- CVE-2026-7366134Monitor
FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
HighCVSS 8.6No exploitEPSS 1%freepbx · frameworkAug 13, 2026
- CVE-2026-4138434Monitor
OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend
HighCVSS 8.5No exploitEPSS 0%openclaw · openclawApr 28, 2026
- CVE-2026-4129434Monitor
OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env File
HighCVSS 8.5No exploitEPSS 0%openclaw · openclawApr 20, 2026
- CVE-2026-8521734Monitor
Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
HighCVSS 8.6No exploitEPSS 0%autodesk · fusionSep 10, 2026