Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-15

4
CRITICAL
12
HIGH
10
MEDIUM
1
LOW
31 CVEs
10.0
CVE-2026-45087

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started

9.9
CVE-2026-44774

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP

9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode wi

9.8
CVE-2026-41176

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC end

8.8
CVE-2026-41489

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From

8.8
CVE-2026-1784

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found

8.6
CVE-2026-41294

OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing

8.3
CVE-2026-27203

eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell

8.3
CVE-2026-16708

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external con

8.2
CVE-2026-46485

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user

7.8
CVE-2026-33092

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acron

7.8
CVE-2026-41384

OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows

7.5
CVE-2026-22750

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configur

7.5
CVE-2026-35650

OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa

7.5
CVE-2026-44417

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth

7.3
CVE-2026-43531

OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file

6.5
CVE-2019-25716

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote

6.1
CVE-2026-22177

OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars

5.7
CVE-2026-30816

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad

5.7
CVE-2026-30817

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac

5.1
CVE-2026-0495

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arb

5.1
CVE-2026-56567

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern

4.5
CVE-2026-0418

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n

4.4
CVE-2026-0232

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin

4.3
CVE-2025-13091

The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on

4.1
CVE-2026-44768

SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to

3.4
CVE-2026-21422

Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setti

CVE-2026-46399

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0

CVE-2026-66065

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to

CVE-2026-73661

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to

CVE-2026-19884

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiri

Frequently Asked Questions

What is CWE-15?

CWE-15 (CWE-15) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-15?

There are 32 CVE records associated with CWE-15 in our database. Of these, 4 are critical severity, 12 are high severity, and 10 are medium severity.

How can I protect against CWE-15 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-15 using AI-powered security agents.

Detect CWE-15 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-15 vulnerabilities across your infrastructure.

Get Started