SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

31 results for “kev-cve-2025-3935” · 1.76 s · cached

Facets · 1 entity types

31 CVE
CVE-2025-49735CVE

CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 1.1%
Match for kev-cve-2025-3935
CVE-2025-1035CVE

CVE-2025-1035

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects…

CVSS 5.7EPSS 9.9%
Match for kev-cve-2025-3935
CVE-2025-36920CVE

CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-3935
CVE-2025-33071CVE

CVE-2025-33071

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 23.2%
Match for kev-cve-2025-3935
CVE-2025-53578CVE

CVE-2025-53578

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local File Inclusion.This issue affects Kipso: f…

CVSS 8.1EPSS 0.4%
Match for kev-cve-2025-3935
CVE-2025-60455CVE

CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

CVSS 8.4EPSS 0.3%
Match for kev-cve-2025-3935
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-3935
CVE-2025-43539CVE

CVE-2025-43539

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 2…

CVSS 8.8EPSS 6.2%apple
Match for kev-cve-2025-3935
CVE-2025-34069CVE

CVE-2025-34069

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP …

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-3935
CVE-2025-4425CVE

CVE-2025-4425

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-3935
CVE-2025-35028CVE

CVE-2025-35028

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is exe…

CVSS 9.1EPSS 5.3%
Match for kev-cve-2025-3935
CVE-2026-37534CVE

CVE-2026-37534

Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer,allows attackers to write to arb…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-3935
CVE-2025-60228CVE

CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2025-3935
CVE-2025-43193CVE

CVE-2025-43193

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-3935
CVE-2025-48539CVE

CVE-2025-48539

In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privil…

CVSS 8.0EPSS 0.3%
Match for kev-cve-2025-3935
CVE-2025-31234CVE

CVE-2025-31234

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An attacker may be able to cause unexpected sys…

CVSS 8.2EPSS 0.6%
Match for kev-cve-2025-3935
CVE-2025-61081CVE

CVE-2025-61081

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Match for kev-cve-2025-3935
CVE-2025-43275CVE

CVE-2025-43275

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-3935
CVE-2025-49739CVE

CVE-2025-49739

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS 8.8EPSS 0.9%
Match for kev-cve-2025-3935
CVE-2025-3835CVE

CVE-2025-3835

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

CVSS 9.6EPSS 2.2%
Match for kev-cve-2025-3935
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.