SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

25 results for “kev-cve-2025-33073” · 1.26 s · cached

Facets · 1 entity types

25 CVE
CVE-2025-33071CVE

CVE-2025-33071

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 23.2%
Match for kev-cve-2025-33073
CVE-2025-32573CVE

CVE-2025-32573

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. This issue affects KiotViet Sync: from n/a through 1…

CVSS 8.5EPSS 0.4%
Match for kev-cve-2025-33073
CVE-2026-43331CVE

CVE-2026-43331

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments() function changes segment registers, invalidatin…

CVSS 5.5EPSS 0.1%linux
Match for kev-cve-2025-33073
CVE-2025-49735CVE

CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 1.1%
Match for kev-cve-2025-33073
CVE-2025-61081CVE

CVE-2025-61081

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Match for kev-cve-2025-33073
CVE-2025-53578CVE

CVE-2025-53578

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local File Inclusion.This issue affects Kipso: f…

CVSS 8.1EPSS 0.5%
Match for kev-cve-2025-33073
CVE-2025-54627CVE

CVE-2025-54627

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 8.8EPSS 0.2%
Match for kev-cve-2025-33073
CVE-2025-40263CVE

CVE-2025-40263

In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`…

EPSS 0.2%
Match for kev-cve-2025-33073
CVE-2025-60455CVE

CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

CVSS 8.4EPSS 0.3%
Match for kev-cve-2025-33073
CVE-2025-32595CVE

CVE-2025-32595

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Krowd krowd allows PHP Local File Inclusion.This issue affects Krowd: f…

CVSS 8.1EPSS 0.8%
Match for kev-cve-2025-33073
CVE-2025-36920CVE

CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-33073
CVE-2026-39429CVE

CVE-2026-39429

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and…

CVSS 8.2EPSS 0.5%kcp
Match for kev-cve-2025-33073
CVE-2025-33067CVE

CVE-2025-33067

Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

CVSS 8.4EPSS 0.5%
Match for kev-cve-2025-33073
CVE-2025-1035CVE

CVE-2025-1035

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects…

CVSS 5.7EPSS 9.9%
Match for kev-cve-2025-33073
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2025-33073
CVE-2025-43330CVE

CVE-2025-43330

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its sandbox.

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-33073
CVE-2025-30403CVE

CVE-2025-30403

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

CVSS 8.1EPSS 0.3%
Match for kev-cve-2025-33073
CVE-2025-43347CVE

CVE-2025-43347

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.

CVSS 9.8EPSS 0.9%
Match for kev-cve-2025-33073
CVE-2025-31633CVE

CVE-2025-31633

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kiamo - Responsive Business Service WordPress Theme allows PHP Local Fi…

CVSS 8.1EPSS 0.8%
Match for kev-cve-2025-33073
CVE-2025-34069CVE

CVE-2025-34069

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP …

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-33073
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.