SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

29 results for “cwe-16” · 0.84 s · cached

Facets · 1 entity types

29 CVEClear type filter
CVE-2026-42916CVE

CVE-2026-42916

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for cwe-16
CVE-2026-34941CVE

CVE-2026-34941

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encodi…

CVSS 8.1EPSS 0.5%
Match for cwe-16
CVE-2025-30416CVE

CVE-2025-30416

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (L…

CVSS 10.0EPSS 0.5%
Match for cwe-16
CVE-2025-47660CVE

CVE-2025-47660

Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a through <= 2.16.

CVSS 8.8EPSS 0.4%
Match for cwe-16
CVE-2026-34906CVE

CVE-2026-34906

Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter…

EPSS 0.9%
Match for cwe-16
CVE-2024-12016CVE

CVE-2024-12016

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection. This issue affects CM News: through 6.0. NOT…

CVSS 9.8EPSS 0.4%
Match for cwe-16
CVE-2026-35416CVE

CVE-2026-35416

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 0.3%microsoft
Match for cwe-16
CVE-2026-3916CVE

CVE-2026-3916

Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS 9.6EPSS 0.3%
Match for cwe-16
CVE-2026-10015CVE

CVE-2026-10015

Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.3%google
Match for cwe-16
CVE-2026-6016CVE

CVE-2026-6016

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of…

CVSS 8.8EPSS 1.0%
Match for cwe-16
CVE-2026-31917CVE

CVE-2026-31917

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.

CVSS 8.5EPSS 0.4%
Match for cwe-16
CVE-2026-36816CVE

CVE-2026-36816

Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability a…

CVSS 7.5EPSS 0.6%
Match for cwe-16
CVE-2026-4960CVE

CVE-2026-4960

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of …

CVSS 8.8EPSS 1.0%
Match for cwe-16
CVE-2026-34336CVE

CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for cwe-16
CVE-2025-4613CVE

CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad t…

CVSS 8.8EPSS 0.6%
Match for cwe-16
CVE-2026-3915CVE

CVE-2026-3915

Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.4%
Match for cwe-16
CVE-2026-5915CVE

CVE-2026-5915

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium secur…

CVSS 8.1EPSS 0.3%google
Match for cwe-16
CVE-2026-44817CVE

CVE-2026-44817

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS 7.8EPSS 0.5%microsoft
Match for cwe-16
CVE-2016-0189CVE

Microsoft Internet Explorer Memory Corruption Vulnerability

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web s…

EPSS 94.1%KEVMicrosoft
Match for cwe-16
CVE-2025-2618CVE

CVE-2025-2618

A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. Th…

CVSS 9.8EPSS 2.0%
Match for cwe-16
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.