SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

28 results for “cwe-310” · 1.66 s · cached

Facets · 1 entity types

28 CVEClear type filter
CVE-2026-3830CVE

CVE-2026-3830

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL inje…

CVSS 8.6EPSS 0.4%
Match for cwe-310
CVE-2025-70031CVE

CVE-2025-70031

An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

CVSS 8.8EPSS 0.2%
Match for cwe-310
CVE-2025-10223CVE

CVE-2025-10223

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with remove…

CVSS 5.4EPSS 0.3%axxonsoft
Match for cwe-310
CVE-2026-0641CVE

CVE-2026-0641

A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_…

CVSS 8.8EPSS 2.6%
Match for cwe-310
CVE-2026-30703CVE

CVE-2026-30703

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input p…

CVSS 9.8EPSS 2.0%
Match for cwe-310
CVE-2025-70030CVE

CVE-2025-70030

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

CVSS 7.5EPSS 0.4%sunbird
Match for cwe-310
CVE-2025-3495CVE

CVE-2025-3495

Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.

CVSS 9.8EPSS 0.7%
Match for cwe-310
CVE-2020-27283CVE

CVE-2020-27283

An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.

CVSS 5.3EPSS 1.0%redlion
Match for cwe-310
CVE-2025-23181CVE

CVE-2025-23181

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for cwe-310
CVE-2025-1104CVE

CVE-2025-1104

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack c…

CVSS 9.8EPSS 3.0%
Match for cwe-310
CVE-2026-34336CVE

CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for cwe-310
CVE-2026-10183CVE

CVE-2026-10183

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. This affects the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument enrollee leads to stack-base…

CVSS 8.8EPSS 0.5%
Match for cwe-310
CVE-2026-1949CVE

CVE-2026-1949

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

CVSS 9.8EPSS 0.6%
Match for cwe-310
CVE-2026-32956CVE

CVE-2026-32956

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

CVSS 9.8EPSS 0.7%
Match for cwe-310
CVE-2026-3703CVE

CVE-2026-3703

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. …

CVSS 9.8EPSS 1.3%
Match for cwe-310
CVE-2026-1951CVE

CVE-2026-1951

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

CVSS 9.8EPSS 0.6%
Match for cwe-310
CVE-2025-41270CVE

CVE-2025-41270

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-310
CVE-2026-10181CVE

CVE-2026-10181

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSysCmd of the file /goform/formSysCmd. Performing a manipulation of the argument submit-url results …

CVSS 8.8EPSS 0.5%
Match for cwe-310
CVE-2026-32530CVE

CVE-2026-32530

Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <= 1.1.18.

CVSS 8.8EPSS 0.4%
Match for cwe-310
CVE-2026-3999CVE

CVE-2026-3999

A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations.

CVSS 8.8EPSS 0.4%pointsharp
Match for cwe-310
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.