SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

48 results for “cwe-840” · 0.72 s · cached

Facets · 3 entity types

35 CVE8 CWE5 CAPEC
CVE-2025-44887CVE

CVE-2025-44887

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44893CVE

CVE-2025-44893

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

CVSS 9.8EPSS 0.7%
Match for cwe-840
CVE-2026-0840CVE

CVE-2026-0840

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argum…

CVSS 8.8EPSS 4.1%
Match for cwe-840
CWE-769CWE

DEPRECATED: Uncontrolled File Descriptor Consumption

This entry has been deprecated because it was a duplicate of CWE-774. All content has been transferred to CWE-774.

Match for cwe-840
CVE-2026-20086CVE

CVE-2026-20086

A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an una…

CVSS 8.6EPSS 0.4%
Match for cwe-840
CVE-2025-41281CVE

CVE-2025-41281

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that al…

CVSS 7.8EPSS 0.5%waterfall-security
Match for cwe-840
CVE-2026-0784CVE

CVE-2026-0784

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP…

CVSS 8.8EPSS 1.7%
Match for cwe-840
CVE-2025-15008CVE

CVE-2025-15008

A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page res…

CVSS 9.8EPSS 0.5%
Match for cwe-840
CWE-516CWE

DEPRECATED: Covert Timing Channel

This weakness can be found at CWE-385.

Match for cwe-840
CVE-2025-15137CVE

CVE-2025-15137

A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934  of the file NTPSyncWithHost.cgi. The manipulation results in command injection. Th…

CVSS 8.8EPSS 11.4%
Match for cwe-840
CVE-2020-8195CVE

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

EPSS 33.0%KEVCitrix
Match for cwe-840
CVE-2025-15136CVE

CVE-2025-15136

A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of the component Management Interface. The manipulati…

CVSS 8.8EPSS 10.7%
Match for cwe-840
CAPEC-679CAPEC

Exploitation of Improperly Configured or Implemented Memory Protections

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1222, CWE-1252, CWE-1257, CWE-1260, CWE-1274 (and 4 more). Related CAPEC patterns: [o…

Detailed
Match for cwe-840
CWE-249CWE

DEPRECATED: Often Misused: Path Manipulation

This entry has been deprecated because of name confusion and an accidental combination of multiple weaknesses. Most of its content has been transferred to CWE-785.

Match for cwe-840
CVE-2026-30809CVE

CVE-2026-30809

Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800

CVSS 8.8EPSS 1.6%
Match for cwe-840
CVE-2025-41274CVE

CVE-2025-41274

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-840
CVE-2020-8196CVE

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

EPSS 26.3%KEVCitrix
Match for cwe-840
CAPEC-121CAPEC

Exploit Non-Production Interfaces

Metadata: standard CAPEC pattern, status stable, likelihood low, severity high. Underlying weaknesses: CWE-489, CWE-1209, CWE-1259, CWE-1267, CWE-1270 (and 5 more). Related CAPEC pattern: [object Obj…

Standard
Match for cwe-840
CVE-2026-0780CVE

CVE-2026-0780

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP…

CVSS 8.8EPSS 1.7%
Match for cwe-840
CVE-2025-44894CVE

CVE-2025-44894

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.