SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

37 results for “kev-cve-2025-22225” · 1.91 s · cached

Facets · 1 entity types

37 CVE
CVE-2025-61081CVE

CVE-2025-61081

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Match for kev-cve-2025-22225
CVE-2025-12274CVE

CVE-2025-12274

A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument …

CVSS 8.8EPSS 0.7%
Match for kev-cve-2025-22225
CVE-2025-60455CVE

CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

CVSS 8.4EPSS 0.3%
Match for kev-cve-2025-22225
CVE-2025-62023CVE

CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

CVSS 9.0EPSS 0.4%
Match for kev-cve-2025-22225
CVE-2024-56122CVE

CVE-2024-56122

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-22225
CVE-2025-57622CVE

CVE-2025-57622

An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-22225
CVE-2025-24256CVE

CVE-2025-24256

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to disclose kernel memory.

CVSS 9.8EPSS 1.2%
Match for kev-cve-2025-22225
CVE-2025-22467CVE

CVE-2025-22467

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

CVSS 8.8EPSS 4.7%
Match for kev-cve-2025-22225
CVE-2025-44022CVE

CVE-2025-44022

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

CVSS 9.8EPSS 1.2%
Match for kev-cve-2025-22225
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-22225
CVE-2025-54627CVE

CVE-2025-54627

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 8.8EPSS 0.2%
Match for kev-cve-2025-22225
CVE-2025-12272CVE

CVE-2025-12272

A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/addressNat. Performing a manipulation of the argument page results in buffer ov…

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-22225
CVE-2025-12232CVE

CVE-2025-12232

A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument…

CVSS 8.8EPSS 4.9%tenda
Match for kev-cve-2025-22225
CVE-2025-12235CVE

CVE-2025-12235

A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow.…

CVSS 8.0EPSS 5.2%
Match for kev-cve-2025-22225
CVE-2025-12271CVE

CVE-2025-12271

A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/RouteStatic. Such manipulation of the argument page leads to buffer overflow. The a…

CVSS 9.8EPSS 1.0%
Match for kev-cve-2025-22225
CVE-2026-46221CVE

CVE-2026-46221

In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device name memory leak The device name allocated via kzalloc() in init_one_mc() is assigned to dev->init_nam…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-22225
CVE-2025-22404CVE

CVE-2025-22404

In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privil…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-22225
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.