CWE-15

External Control of System or Configuration Setting

Parent: CWE-642 - External Control of Critical State Data

One or more system settings or configuration elements can be externally controlled by a user.

58 vulnerabilities with CWE-15
CVE-2024-39799 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39798 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39795 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Permission Bypass
CVSS 9.1
CVE-2024-39794 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39793 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39790 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39789 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
CVSS 9.1
CVE-2024-39788 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
CVSS 9.1
CVE-2024-39602 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39280 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-38666 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Command Injection
CVSS 9.1
CVE-2024-54097 HIGH
HiView - Info Disclosure
CVSS 7.3
CVE-2024-51544 HIGH
Service Control - Info Disclosure
CVSS 8.2
CVE-2024-51543 HIGH
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 8.2
CVE-2024-50358 HIGH
Advantech - External Control of System or Configuration Setting
CVSS 7.2
CVE-2024-10979 HIGH
PostgreSQL <17.1-12.21 - Code Injection
CVSS 8.8
CVE-2024-21583 MEDIUM
github.com/gitpod-io/gitpod - Info Disclosure
CVSS 4.1
CVE-2024-4326 CRITICAL
parisneo/lollms-webui <9.3 - RCE
CVSS 9.8
CVE-2024-23639 MEDIUM
Micronaut Framework - Info Disclosure
CVSS 5.1
CVE-2023-6154 HIGH
Bitdefender - Code Injection
CVSS 7.8
CVE-2023-50252 HIGH
Dompdf Php-svg-lib < 0.5.1 - Insecure Deserialization
CVSS 8.3
CVE-2023-46764 MEDIUM
Background Apps - Info Disclosure
CVSS 5.3
CVE-2023-46248 CRITICAL
Cody AI VSCode Extension <0.14.0 - RCE
CVSS 9.0
CVE-2023-43323 MEDIUM
mooSocial 3.1.8 - SSRF
CVSS 6.5
CVE-2023-4704 MEDIUM
instantsoft/icms2 <2.16.1 - Elevation of Privilege
CVSS 4.9
Details
Vulnerabilities 58