Weaknesses of type CWE-15

81 results

Controle Externo de Configurações do Sistema

A aplicação permite que um atacante modifique configurações críticas do sistema ou da aplicação através de entrada externa (parâmetros, arquivos, variáveis de ambiente, etc.), sem validação adequada. Isso pode levar ao comprometimento da segurança, funcionamento incorreto ou acesso não autorizado.

Example

Um serviço web aceita um parâmetro 'debug_mode' vindo da requisição HTTP e o usa diretamente para ligar/desligar logs sensíveis ou alternar validações de segurança. Um atacante manda debug_mode=true e expõe dados internos ou desativa proteções.

How to mitigate

Nunca confie em entradas externas para configurações sensíveis. Use apenas fontes confiáveis (arquivo de config protegido no servidor, variáveis de ambiente do deployment) e valide/sanitize rigorosamente qualquer entrada que possa impactar comportamento de segurança.

CVE-2023-46764Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliEPSS 0.3%CVE-2026-73661HIGHFreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted BackupEPSS 0.3%CVE-2024-51543HIGHInformation DisclosureEPSS 0.3%CVE-2026-87987CRITICALAn arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable EPSS 0.3%CVE-2024-54097HIGHSecurity vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and inteEPSS 0.3%CVE-2025-13091MEDIUMShopire <= 1.0.57 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin InstallEPSS 0.3%CVE-2025-43792LOWRemote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.EPSS 0.3%CVE-2025-8283LOWNetavark: podman: netavark may resolve hostnames to unexpected hostsEPSS 0.3%CVE-2026-54918MEDIUMNetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) enables SSRF and test-data substitution from CIEPSS 0.3%CVE-2026-13745HIGHArbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOMEEPSS 0.3%CVE-2026-66065HIGHOuroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)EPSS 0.3%CVE-2026-46399CRITICALAuthenticated Remote Code Execution via File OverwriteEPSS 0.3%CVE-2026-19593CRITICALOpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If tEPSS 0.3%CVE-2026-30816MEDIUMArbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53EPSS 0.3%CVE-2024-11166HIGHTraffic Alert and Collision Avoidance System (TCAS) II has an External Control of System or Configuration Setting vulnerabilityEPSS 0.3%CVE-2024-23639MEDIUMmicronaut-core management endpoints vulnerable to drive-by localhost attackEPSS 0.3%CVE-2026-44768MEDIUMSecurity misconfiguration in SAP CRM (WebClient UI)EPSS 0.3%CVE-2025-62527HIGHTaguette vulnerable to password reset link poisoningEPSS 0.3%CVE-2025-41452MEDIUMPost auth nginx configuration injection in Danfoss AK-SM8xxA SeriesEPSS 0.3%CVE-2026-0418MEDIUMCertain NETGEAR devices allow administrators to tamper with systemEPSS 0.2%