SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-1018” · 1.65 s · cached

Facets · 3 entity types

31 CVE18 CWE1 CAPEC
CWE-1187CWE

DEPRECATED: Use of Uninitialized Resource

This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908.

Match for cwe-1018
CWE-596CWE

DEPRECATED: Incorrect Semantic Object Comparison

This weakness has been deprecated. It was poorly described and difficult to distinguish from other entries. It was also inappropriate to assign a separate ID solely because of domain-specific consi…

Match for cwe-1018
CWE-769CWE

DEPRECATED: Uncontrolled File Descriptor Consumption

This entry has been deprecated because it was a duplicate of CWE-774. All content has been transferred to CWE-774.

Match for cwe-1018
CWE-92CWE

DEPRECATED: Improper Sanitization of Custom Special Characters

This entry has been deprecated. It originally came from PLOVER, which sometimes defined "other" and "miscellaneous" categories in order to satisfy exhaustiveness requirements for taxonomies. Within t…

Match for cwe-1018
CWE-373CWE

DEPRECATED: State Synchronization Error

This entry was deprecated because it overlapped the same concepts as race condition (CWE-362) and Improper Synchronization (CWE-662).

Match for cwe-1018
CVE-2026-10189CVE

CVE-2026-10189

A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the function cgiSysTimeInfoSet of the file /bin/httpd. The manipulation of the argument sec leads to stack-based …

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2025-23176CVE

CVE-2025-23176

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2026-11528CVE

CVE-2026-11528

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of …

CVSS 8.8EPSS 0.5%
Match for cwe-1018
CVE-2025-55058CVE

CVE-2025-55058

CWE-20 Improper Input Validation

CVSS 4.5EPSS 0.3%maxum
Match for cwe-1018
CWE-391CWE

Unchecked Error Condition

[PLANNED FOR DEPRECATION. SEE MAINTENANCE NOTES AND CONSIDER CWE-252, CWE-248, OR CWE-1069.] Ignoring exceptions and other error conditions may allow an attacker to induce unexpected behavior unnotic…

Match for cwe-1018
CWE-592CWE

DEPRECATED: Authentication Bypass Issues

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

Match for cwe-1018
CVE-2025-47660CVE

CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

CVSS 8.8EPSS 0.4%
Match for cwe-1018
CVE-2025-23180CVE

CVE-2025-23180

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for cwe-1018
CWE-249CWE

DEPRECATED: Often Misused: Path Manipulation

This entry has been deprecated because of name confusion and an accidental combination of multiple weaknesses. Most of its content has been transferred to CWE-785.

Match for cwe-1018
CWE-218CWE

DEPRECATED: Failure to provide confidentiality for stored data

This weakness has been deprecated because it was a duplicate of CWE-493. All content has been transferred to CWE-493.

Match for cwe-1018
CVE-2025-2097CVE

CVE-2025-2097

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The man…

CVSS 9.8EPSS 7.2%
Match for cwe-1018
CWE-458CWE

DEPRECATED: Incorrect Initialization

This weakness has been deprecated because its name and description did not match. The description duplicated CWE-454, while the name suggested a more abstract initialization problem. Please refer to …

Match for cwe-1018
CWE-423CWE

DEPRECATED: Proxied Trusted Channel

This entry has been deprecated because it was a duplicate of CWE-441. All content has been transferred to CWE-441.

Match for cwe-1018
CWE-545CWE

DEPRECATED: Use of Dynamic Class Loading

This weakness has been deprecated because it partially overlaps CWE-470, it describes legitimate programmer behavior, and other portions will need to be integrated into other entries.

Match for cwe-1018
CVE-2025-55048CVE

CVE-2025-55048

Multiple CWE-78

CVSS 9.8EPSS 0.6%
Match for cwe-1018
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.