SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

38 results for “kev-cve-2025-24054” · 0.69 s · cached

Facets · 1 entity types

38 CVE
CVE-2025-8654CVE

CVE-2025-8654

Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwoo…

CVSS 8.8EPSS 0.8%
Match for kev-cve-2025-24054
CVE-2025-4422CVE

CVE-2025-4422

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-24054
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-24054
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2025-24054
CVE-2025-70420CVE

CVE-2025-70420

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS 0.0%
Match for kev-cve-2025-24054
CVE-2025-62023CVE

CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

CVSS 9.0EPSS 0.4%
Match for kev-cve-2025-24054
CVE-2025-5254CVE

CVE-2025-5254

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS. This issue affects Kron PAM: before 3.7.

CVSS 6.1EPSS 0.4%
Match for kev-cve-2025-24054
CVE-2025-4421CVE

CVE-2025-4421

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.3%
Match for kev-cve-2025-24054
CVE-2025-20654CVE

CVE-2025-20654

In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is…

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-24054
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for kev-cve-2025-24054
CVE-2025-24252CVE

CVE-2025-24252

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tv…

CVSS 8.8EPSS 1.3%
Match for kev-cve-2025-24054
CVE-2025-57622CVE

CVE-2025-57622

An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-24054
CVE-2026-0654CVE

CVE-2026-0654

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arb…

CVSS 8.0EPSS 0.3%
Match for kev-cve-2025-24054
CVE-2025-27060CVE

CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

CVSS 8.8EPSS 0.1%
Match for kev-cve-2025-24054
CVE-2025-36920CVE

CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-24054
CVE-2025-54466CVE

CVE-2025-54466

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum p…

CVSS 9.8EPSS 17.3%
Match for kev-cve-2025-24054
CVE-2026-22454CVE

CVE-2026-22454

Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5.

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-24054
CVE-2026-45760CVE

CVE-2026-45760

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…

CVSS 8.1EPSS 0.4%
Match for kev-cve-2025-24054
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.