Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-15

External Control of System or Configuration Setting

One or more system settings or configuration elements can be externally controlled by a user.

70
Assigned CVEs
205th
Commonality Rank
7.5
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-15 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2021
4 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-41176CRITICAL
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`,
Apr 23, 20269.868NOYES
CVE-2026-45087CRITICAL
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to
May 27, 202610.046NOYES
CVE-2024-39280CRITICAL
An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitr
Jan 14, 20259.141NONO
CVE-2026-1784HIGH
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a
Jun 2, 20268.836NONO
CVE-2026-44774CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissio
May 15, 20269.936NONO
CVE-2026-22708CRITICAL
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still
Jan 14, 20269.836NONO
CVE-2026-46485HIGH
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the m
Jul 15, 20268.235NONO
CVE-2023-50252CRITICAL
php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use>
Dec 12, 20239.835NONO
CVE-2026-44417HIGH
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilitie
May 22, 20267.534NONO
CVE-2026-35650HIGH
OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent s
Apr 10, 20268.834NONO
View all 70 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
9%
10%
4.0-4.9
10%
19%
5.0-5.9
16%
6.0-6.9
34%
26%
7.0-7.9
23%
11%
8.0-8.9
16%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.4% of CVEs· 91st percentile
Nuclei
2 CVEs
2.9% of CVEs· 92nd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products