CWE-15: External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
71 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4326 — Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui
- CVE-2026-6973 — An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
- CVE-2024-39800 — Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli
- CVE-2024-39799 — Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli
- CVE-2024-39798 — Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli
- CVE-2024-39795 — Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000
- CVE-2024-39794 — Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000
- CVE-2024-39793 — Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000
- CVE-2024-39790 — Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A
- CVE-2024-39789 — Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A
- CVE-2024-39788 — Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A
- CVE-2024-39602 — An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210
- CVE-2024-39280 — An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030
- CVE-2024-38666 — An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC300
- CVE-2024-51544 — Service Control
- CVE-2024-51543 — Information Disclosure
- CVE-2024-10979 — PostgreSQL PL/Perl environment variable changes execute arbitrary code
- CVE-2025-0425 — Local Privilege Escalation via Config Manipulation
- CVE-2026-45087 — Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user open
Recently published
- CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repos
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user open
- CVE-2026-16708 — IBM Db2 Mirror for i is affected by multiple vulnerabilities
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiri
- CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)
- CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.
- CVE-2026-46485 — Dash: Users can write to config despire permissions (OIDC tested)
- CVE-2026-44768 — Security misconfiguration in SAP CRM (WebClient UI)
- CVE-2026-0418 — Certain NETGEAR devices allow administrators to tamper with system
- CVE-2026-46399 — Authenticated Remote Code Execution via File Overwrite
- CVE-2026-1784 — Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection
- CVE-2019-25716 — Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet
- CVE-2026-45087 — Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
- CVE-2026-41489 — Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks
- CVE-2026-6973 — An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
- CVE-2026-43531 — OpenClaw < 2026.4.9 - Environment Variable Injection via Workspace .env File
- CVE-2026-41384 — OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend
- CVE-2026-41294 — OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env File
- CVE-2026-0232 — Cortex XDR Agent: Local Administrator can disable the agent on Windows