Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC end
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing
eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external con
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user
Local privilege escalation due to improper handling of environment variables. The following products are affected: Acron
OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configur
OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth
OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arb
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin
The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to
Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setti
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to
FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiri
Frequently Asked Questions
What is CWE-15?
CWE-15 (CWE-15) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-15?
There are 32 CVE records associated with CWE-15 in our database. Of these, 4 are critical severity, 12 are high severity, and 10 are medium severity.
How can I protect against CWE-15 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-15 using AI-powered security agents.
Detect CWE-15 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-15 vulnerabilities across your infrastructure.
Get Started