CWE-15
CWE-15 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-15, highest CVSS first.
- HIGH 7.4CVE-2026-105294public PoC
Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to pers…
- UNSCOREDCVE-2026-94577
A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user or local process that can manipulate the pr…
- UNSCOREDCVE-2026-103442
External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.