CWE-15
External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
58 vulnerabilities with CWE-15
CVE-2026-41384
HIGH
OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend
CVSS 7.8
CVE-2026-41294
HIGH
OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env File
CVSS 8.6
CVE-2026-0232
MEDIUM
Cortex XDR Agent: Local Administrator can disable the agent on Windows
CVE-2026-35650
HIGH
OpenClaw < 2026.3.22 - Environment Variable Override Bypass via Inconsistent Sanitization
CVSS 7.5
CVE-2026-33092
HIGH
Acronis True Image Oem < 42571 - Privilege Escalation
CVSS 7.8
CVE-2026-22750
HIGH
SSL bundle configuration silently bypassed in Spring Cloud Gateway
CVSS 7.5
CVE-2026-30817
MEDIUM
Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53
CVSS 5.7
CVE-2026-30816
MEDIUM
Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53
CVSS 5.7
CVE-2026-22177
MEDIUM
OpenClaw < 2026.2.21 - Environment Variable Injection via Config env.vars
CVSS 6.1
CVE-2026-21422
LOW
Dell PowerScale OneFS 9.10.0-9.12.0 - Privilege Escalation
CVSS 3.4
CVE-2026-27203
HIGH
eBay API MCP Server - Code Injection
CVSS 8.3
CVE-2026-22708
CRITICAL
Anysphere Cursor < 2.3 - Command Injection
CVSS 9.8
CVE-2026-0495
MEDIUM
SAP Fiori App - Privilege Escalation
CVSS 5.1
CVE-2025-13091
MEDIUM
Shopire WordPress Theme <=1.0.57 - Privilege Escalation
CVSS 4.3
CVE-2025-64726
HIGH
Socket Firewall <0.15.5 - RCE
CVE-2025-62527
HIGH
Taguette <1.5.0 - CSRF
CVSS 7.1
CVE-2025-43792
MEDIUM
Liferay Portal <7.4.3.105 - Info Disclosure
CVSS 5.3
CVE-2025-41452
MEDIUM
Danfoss AK-SM8xxA <4.3.1 - DoS
CVE-2025-8283
LOW
netavark - Info Disclosure
CVSS 3.7
CVE-2025-27889
LOW
Wing FTP Server <7.4.4 - Code Injection
CVSS 3.4
CVE-2025-30512
MEDIUM
Growatt Cloud Portal <= 3.6.0 - Unauthenticated Remote Configuration Manipulation
CVSS 6.5
CVE-2025-27253
MEDIUM
GE Vernova UR IED <8.60 - Info Disclosure
CVSS 6.1
CVE-2025-0425
HIGH
bestinformed Infoclient - Privilege Escalation
CVE-2024-11166
HIGH
TCAS II - DoS
CVE-2024-39800
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
Details
Vulnerabilities
58