CWE-15
External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
65 vulnerabilities with CWE-15
CVE-2025-27889
LOW
Wing FTP Server <7.4.4 - Code Injection
CVSS 3.4
CVE-2025-30512
MEDIUM
Growatt Cloud Portal <= 3.6.0 - Unauthenticated Remote Configuration Manipulation
CVSS 6.5
CVE-2025-27253
MEDIUM
GE Vernova UR IED <8.60 - Info Disclosure
CVSS 6.1
CVE-2025-0425
HIGH
bestinformed Infoclient - Privilege Escalation
CVE-2024-11166
HIGH
Traffic Alert and Collision Avoidance System (TCAS) II - Denial of Service via Comm-A Identity Request
CVE-2024-39800
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39799
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39798
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39795
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Permission Bypass
CVSS 9.1
CVE-2024-39794
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39793
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39790
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
CVSS 9.1
CVE-2024-39789
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
CVSS 9.1
CVE-2024-39788
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
CVSS 9.1
CVE-2024-39602
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-39280
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
CVSS 9.1
CVE-2024-38666
CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Command Injection
CVSS 9.1
CVE-2024-54097
HIGH
Huawei EMUI and HarmonyOS - External Control of System Setting in HiView Module
CVSS 7.3
CVE-2024-51544
HIGH
ABB ASPECT Enterprise NEXUS and MATRIX Series < 3.08.03 - Unauthenticated Service Control and Configuration Modification
CVSS 8.2
CVE-2024-51543
HIGH
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 8.2
CVE-2024-50358
HIGH
Advantech - External Control of System or Configuration Setting
CVSS 7.2
CVE-2024-10979
HIGH
PostgreSQL <17.1-12.21 - Code Injection
CVSS 8.8
CVE-2024-21583
MEDIUM
github.com/gitpod-io/gitpod - Info Disclosure
CVSS 4.1
CVE-2024-4326
CRITICAL
lollms_web_ui < 9.5 - Remote Code Execution via Settings Bypass
CVSS 9.8
CVE-2024-23639
MEDIUM
Micronaut Framework - Info Disclosure
CVSS 5.1
Details
Vulnerabilities
65