CWE-15
60 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-15page 1 of 2
- CVE-2019-25716MEDIUMCVSS 6.5EG 6.52026-06-01
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malform…
- CVE-2021-27406HIGHCVSS 8.8EG 8.82022-10-14
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance wit…
- CVE-2021-31338HIGHCVSS 7.8EG 7.82021-08-19
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privilege…
- CVE-2021-3707MEDIUMCVSS 5.5EG 5.52021-08-16
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3708, to execute any OS commands on …
- CVE-2021-38453CRITICALCVSS 9.1EG 9.12021-10-22
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
- CVE-2022-41582HIGHCVSS 7.5EG 7.52022-10-14
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.
- CVE-2023-32076MEDIUMCVSS 5.5EG 5.52023-05-10
in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and allows users to configure the behavior of the framework. The files are from directories following the XDG base directo…
- CVE-2023-32349HIGHCVSS 8.0EG 8.02023-05-22
Version 00.07.03.4 and prior of Teltonika’s RUT router firmware contain a packet dump utility that contains proper validation for filter parameters. However, variables for validation checks are stored in an external configuration file. …
- CVE-2023-3321HIGHCVSS 7.0EG 7.02023-07-24
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabil…
- CVE-2023-43323MEDIUMCVSS 6.5EG 6.52023-09-28
mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShare…
- CVE-2023-46248CRITICALCVSS 9.0EG 9.02023-10-31
Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditions. An attacker in control of a malicious repository could …
- CVE-2023-46764MEDIUMCVSS 5.3EG 5.32023-11-08
Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.
- CVE-2023-4704MEDIUMCVSS 4.9EG 8.82023-09-01
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- CVE-2023-50252HIGHCVSS 8.3EG 8.32023-12-12
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>` tag to the `<image>` tag. The problem pops up especially …
- CVE-2023-6154HIGHCVSS 7.8EG 7.82024-04-01
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and po…
- CVE-2024-10979HIGHCVSS 8.8EG 8.82024-11-14
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attac…
- CVE-2024-11166HIGHCVSS 7.1EG 0.02025-01-22
For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a ground station and issue a Comm-A Identity Request. This action can set the Sensitivity Level Control (SLC) to the lowest s…
- CVE-2024-1488HIGHCVSS 8.0EG 8.02024-02-15
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the c…
- CVE-2024-21583MEDIUMCVSS 4.1EG 4.12024-07-19
Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github…
- CVE-2024-23639MEDIUMCVSS 5.1EG 5.12024-02-09
Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are sus…
- CVE-2024-38666CRITICALCVSS 9.1EG 9.12025-01-14
An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an…
- CVE-2024-39280CRITICALCVSS 9.1EG 9.12025-01-14
An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticate…
- CVE-2024-39602CRITICALCVSS 9.1EG 9.12025-01-14
An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HT…
- CVE-2024-39788CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated H…
- CVE-2024-39789CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated H…
- CVE-2024-39790CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated H…
- CVE-2024-39793CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticat…
- CVE-2024-39794CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticat…
- CVE-2024-39795CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticat…
- CVE-2024-39798CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can…
- CVE-2024-39799CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can…
- CVE-2024-39800CRITICALCVSS 9.1EG 9.12025-01-14
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can…
- CVE-2024-4326CRITICALCVSS 9.8EG 9.82024-05-16
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypas…
- CVE-2024-50358HIGHCVSS 7.2EG 7.22024-11-26
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerabilit…
- CVE-2024-51543HIGHCVSS 8.2EG 8.22024-12-05
Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-51544HIGHCVSS 8.2EG 8.22024-12-05
Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-54097HIGHCVSS 7.3EG 7.32024-12-12
Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.
- CVE-2025-0425HIGHCVSS 8.5EG 0.02025-02-18
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as the "bestinformed Infoclient" runs with el…
- CVE-2025-27253MEDIUMCVSS 6.1EG 6.12025-03-10
A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of t…
- CVE-2025-27889LOWCVSS 3.4EG 3.42025-07-10
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the …
- CVE-2025-30512MEDIUMCVSS 6.5EG 6.52025-04-15
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).
- CVE-2025-41452MEDIUMCVSS 6.8EG 0.02025-08-22
Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional condi…
- CVE-2025-43792MEDIUMCVSS 5.3EG 5.32025-09-15
Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not p…
- CVE-2025-62527HIGHCVSS 7.1EG 7.12025-10-20
Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to s…
- CVE-2025-64726HIGHCVSS 7.3EG 0.02025-11-13
Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by blocking dangerous packages. Socket Firewall binary versions (separate from installers) prior to 0.15.5 are vulnerable…
- CVE-2025-8283LOWCVSS 3.7EG 3.72025-07-28
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When cr…
- CVE-2026-0232MEDIUMCVSS 4.0EG 4.02026-04-13
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
- CVE-2026-0495MEDIUMCVSS 5.1EG 5.12026-01-13
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and av…
- CVE-2026-1784HIGHCVSS 8.8EG 8.82026-06-02
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controll…
- CVE-2026-22708CRITICALCVSS 9.8EG 9.82026-01-14
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without…
Map vulnerabilities like CWE-15 to your infrastructure
EchelonGraph correlates every CVE — across CWE-15 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →