SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

31 results for “cwe-1018” · 1.76 s · cached

Facets · 1 entity types

31 CVEClear type filter
CVE-2026-20418CVE

CVE-2026-20418

In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is…

CVSS 9.8EPSS 0.4%
Match for cwe-1018
CVE-2026-4318CVE

CVE-2026-4318

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform/formApLbConfig. This manipulation of the argument loadBalanceNameOld causes bu…

CVSS 8.8EPSS 0.8%
Match for cwe-1018
CVE-2026-10192CVE

CVE-2026-10192

A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function set_local_time_0 of the file /bin/httpd. Such manipulation of the argument Time leads to stack-based bu…

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2026-6016CVE

CVE-2026-6016

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of…

CVSS 8.8EPSS 1.0%
Match for cwe-1018
CVE-2026-3918CVE

CVE-2026-3918

Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.3%
Match for cwe-1018
CVE-2026-49771CVE

CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10W…

CVSS 7.6EPSS 0.4%
Match for cwe-1018
CVE-2025-56106CVE

CVE-2025-56106

OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua…

CVSS 8.8EPSS 2.8%
Match for cwe-1018
CVE-2025-56089CVE

CVE-2025-56089

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev…

CVSS 8.8EPSS 2.8%
Match for cwe-1018
CVE-2025-11326CVE

CVE-2025-11326

A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz can lead to stac…

CVSS 8.8EPSS 1.2%
Match for cwe-1018
CVE-2025-31710CVE

CVE-2025-31710

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

CVSS 8.4EPSS 0.4%
Match for cwe-1018
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for cwe-1018
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.