SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-1018” · 1.69 s · cached

Facets · 3 entity types

31 CVE18 CWE1 CAPEC
CVE-2026-6016CVE

CVE-2026-6016

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of…

CVSS 8.8EPSS 1.0%
Match for cwe-1018
CVE-2026-3918CVE

CVE-2026-3918

Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.3%
Match for cwe-1018
CVE-2026-49771CVE

CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10W…

CVSS 7.6EPSS 0.4%
Match for cwe-1018
CVE-2025-56106CVE

CVE-2025-56106

OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua…

CVSS 8.8EPSS 2.8%
Match for cwe-1018
CVE-2025-56089CVE

CVE-2025-56089

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev…

CVSS 8.8EPSS 2.8%
Match for cwe-1018
CWE-132CWE

DEPRECATED: Miscalculated Null Termination

This entry has been deprecated because it was a duplicate of CWE-170. All content has been transferred to CWE-170.

Match for cwe-1018
CVE-2025-11326CVE

CVE-2025-11326

A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz can lead to stac…

CVSS 8.8EPSS 1.2%
Match for cwe-1018
CWE-217CWE

DEPRECATED: Failure to Protect Stored Data from Modification

This entry has been deprecated because it incorporated and confused multiple weaknesses. The issues formerly covered in this entry can be found at CWE-766 and CWE-767.

Match for cwe-1018
CVE-2025-31710CVE

CVE-2025-31710

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

CVSS 8.4EPSS 0.4%
Match for cwe-1018
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for cwe-1018
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.