Перейти к содержимому
Noroxi

CWE-15 · 81 записей

External Control of System or Configuration Setting

CVE этого класса

82 записей

  • CVE-2024-39280
    46В плане

    An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505.

    КритическаяCVSS 9,1Эксплойта нетEPSS 34 %

    wavlink · wl-wn533a8 firmware14 янв. 2025 г.

  • CVE-2023-50252
    46В плане

    php-svg-lib unsafe attributes merge when parsing `use` tag

    КритическаяCVSS 9,8Эксплойта нетEPSS 24 %

    dompdf · php-svg-lib12 дек. 2023 г.

  • CVE-2024-38666
    42В плане

    An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505

    КритическаяCVSS 9,1Эксплойта нетEPSS 19 %

    wavlink · wl-wn533a8 firmware14 янв. 2025 г.

  • CVE-2026-45087
    40В плане

    Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode

    КритическаяCVSS 10,0Готовый эксплойтEPSS 1 %

    hahwul · dalfox27 мая 2026 г.

  • CVE-2026-87987
    40В плане

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    mistralai · mistral-vibe11 сент. 2026 г.

  • CVE-2024-51544
    39Наблюдать

    Service Control vulnerabilities allow access to service restart requests and vm configuration settings.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %

    abb · aspect-ent-12 firmware5 дек. 2024 г.

  • CVE-2024-4326
    39Наблюдать

    Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    lollms · lollms web ui16 мая 2024 г.

  • CVE-2026-19593
    39Наблюдать

    OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    openai · codex desktop1 сент. 2026 г.

  • CVE-2024-39602
    37Наблюдать

    An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    wavlink · wl-wn533a8 firmware14 янв. 2025 г.

  • CVE-2026-46399
    37Наблюдать

    Authenticated Remote Code Execution via File Overwrite

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    haxtheweb · haxcms-nodejs5 июн. 2026 г.

  • CVE-2024-10979
    36Наблюдать

    PostgreSQL PL/Perl environment variable changes execute arbitrary code

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    postgresql · postgresql14 нояб. 2024 г.

  • CVE-2021-38453
    36Наблюдать

    Some API functions allow interaction with the registry, which includes reading values as well as data modification.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    auvesy · versiondog22 окт. 2021 г.

  • CVE-2023-46248
    35Наблюдать

    Overwrite of builtin Cody commands facilitates RCE

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sourcegraph · cody31 окт. 2023 г.

  • CVE-2023-32349
    35Наблюдать

    Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter pa

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    teltonika-networks · rut200 firmware22 мая 2023 г.

  • CVE-2021-27406
    35Наблюдать

    PerFact OpenVPN-Client

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    perfact · openvpn-client14 окт. 2022 г.

  • CVE-2025-27889
    35Наблюдать

    Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    wftpserver · wing ftp server10 июл. 2025 г.

  • CVE-2023-3321
    35Наблюдать

    Code Execution through Writable Mosquitto Configuration File

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    abb · zenon24 июл. 2023 г.

  • CVE-2024-51543
    35Наблюдать

    Information Disclosure

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    abb · aspect-ent-12 firmware5 дек. 2024 г.

  • CVE-2026-1784
    35Наблюдать

    Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    redhat · openshift container platform2 июн. 2026 г.

  • CVE-2026-41489
    35Наблюдать

    Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    pi-hole · pi-hole11 мая 2026 г.

  • CVE-2026-73661
    34Наблюдать

    FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    freepbx · framework13 авг. 2026 г.

  • CVE-2026-41384
    34Наблюдать

    OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    openclaw · openclaw28 апр. 2026 г.

  • CVE-2026-41294
    34Наблюдать

    OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env File

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    openclaw · openclaw20 апр. 2026 г.

  • CVE-2026-85217
    34Наблюдать

    Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    autodesk · fusion10 сент. 2026 г.

  • CVE-2025-0425
    34Наблюдать

    Local Privilege Escalation via Config Manipulation

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    cordaware · bestinformed infoclient18 февр. 2025 г.

Все классы уязвимостей