SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

32 results for “kev-cve-2025-27038” · 0.79 s · cached

Facets · 1 entity types

32 CVE
CVE-2025-70420CVE

CVE-2025-70420

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS 0.0%
Match for kev-cve-2025-27038
CVE-2025-12638CVE

CVE-2025-12638

Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerability arises because the function uses Python's tar…

CVSS 8.0EPSS 0.7%
Match for kev-cve-2025-27038
CVE-2025-7039CVE

CVE-2025-7039

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temp…

CVSS 3.7EPSS 0.4%
Match for kev-cve-2025-27038
CVE-2026-6209CVE

CVE-2026-6209

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-27038
CVE-2025-21370CVE

CVE-2025-21370

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

CVSS 8.8EPSS 0.5%
Match for kev-cve-2025-27038
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-27038
CVE-2026-50265CVE

CVE-2026-50265

Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292

EPSS 0.0%
Match for kev-cve-2025-27038
CVE-2025-66738CVE

CVE-2025-66738

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

CVSS 8.8EPSS 0.6%yealink
Match for kev-cve-2025-27038
CVE-2025-4538CVE

CVE-2025-4538

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of the argument File leads to unrestricted up…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-27038
CVE-2025-1035CVE

CVE-2025-1035

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects…

CVSS 5.7EPSS 9.9%
Match for kev-cve-2025-27038
CVE-2025-35028CVE

CVE-2025-35028

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is exe…

CVSS 9.1EPSS 5.3%
Match for kev-cve-2025-27038
CVE-2025-21178CVE

CVE-2025-21178

Visual Studio Remote Code Execution Vulnerability

CVSS 8.8EPSS 1.6%
Match for kev-cve-2025-27038
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.