SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

31 results for “cwe-1018” · 1.91 s · cached

Facets · 1 entity types

31 CVEClear type filter
CVE-2026-10189CVE

CVE-2026-10189

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based …

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2025-23176CVE

CVE-2025-23176

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2026-11528CVE

CVE-2026-11528

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of …

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2025-55058CVE

CVE-2025-55058

CWE-20 Improper Input Validation

CVSS 4.5EPSS 0.3%maxum
Match for cwe-1018
CVE-2025-47660CVE

CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

CVSS 8.8EPSS 0.4%
Match for cwe-1018
CVE-2025-23180CVE

CVE-2025-23180

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for cwe-1018
CVE-2025-2097CVE

CVE-2025-2097

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The man…

CVSS 9.8EPSS 7.2%
Match for cwe-1018
CVE-2025-55048CVE

CVE-2025-55048

Multiple CWE-78

CVSS 9.8EPSS 0.6%
Match for cwe-1018
CVE-2026-10188CVE

CVE-2026-10188

A flaw has been found in Tenda W12 3.0.0.7(4763). This affects the function cgistaKickOff of the file /bin/httpd. Executing a manipulation of the argument staMac can lead to stack-based buffer overfl…

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2025-60946CVE

CVE-2025-60946

Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha.

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2025-55055CVE

CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS 9.8EPSS 0.8%
Match for cwe-1018
CVE-2026-11180CVE

CVE-2026-11180

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS 6.5EPSS 0.2%google
Match for cwe-1018
CVE-2026-11518CVE

CVE-2026-11518

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument f…

CVSS 4.3EPSS 0.4%
Match for cwe-1018
CVE-2026-46718CVE

CVE-2026-46718

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended …

CVSS 6.5EPSS 0.7%apache
Match for cwe-1018
CVE-2025-15196CVE

CVE-2025-15196

A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The att…

CVSS 7.3EPSS 0.4%code-projects
Match for cwe-1018
CVE-2026-3808CVE

CVE-2026-3808

A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument webSi…

CVSS 8.8EPSS 1.0%
Match for cwe-1018
CVE-2026-20797CVE

CVE-2026-20797

A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.

CVSS 9.8EPSS 0.8%
Match for cwe-1018
CVE-2025-11122CVE

CVE-2025-11122

A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer…

CVSS 8.8EPSS 0.8%tenda
Match for cwe-1018
CVE-2025-10418CVE

CVE-2025-10418

A weakness has been identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_students.php. This manipulation of the argume…

CVSS 8.8EPSS 0.4%
Match for cwe-1018
CVE-2026-10015CVE

CVE-2026-10015

Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.3%google
Match for cwe-1018
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.