One or more system settings or configuration elements can be externally controlled by a user.
Volume of CVEs assigned to CWE-15 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41176CRITICAL Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, | Apr 23, 2026 | 9.8 | 68 | NO | YES |
CVE-2026-45087CRITICAL Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to | May 27, 2026 | 10.0 | 46 | NO | YES |
CVE-2024-39280CRITICAL An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitr | Jan 14, 2025 | 9.1 | 41 | NO | NO |
CVE-2026-1784HIGH The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a | Jun 2, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-44774CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissio | May 15, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-22708CRITICAL Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still | Jan 14, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-46485HIGH Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the m | Jul 15, 2026 | 8.2 | 35 | NO | NO |
CVE-2023-50252CRITICAL php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use> | Dec 12, 2023 | 9.8 | 35 | NO | NO |
CVE-2026-44417HIGH The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilitie | May 22, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-35650HIGH OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environment policy through inconsistent s | Apr 10, 2026 | 8.8 | 34 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.