SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

36 results for “kev-cve-2025-42599” · 0.82 s · cached

Facets · 1 entity types

36 CVE
CVE-2025-66419CVE

CVE-2025-66419

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent…

CVSS 10.0EPSS 0.3%
Match for kev-cve-2025-42599
CVE-2026-42799CVE

CVE-2026-42799

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects …

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-42599
CVE-2025-36920CVE

CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-42599
CVE-2025-4404CVE

CVE-2025-4404

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by defa…

CVSS 9.1EPSS 2.0%
Match for kev-cve-2025-42599
CVE-2025-9748CVE

CVE-2025-9748

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing manipulation of the argument…

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-42599
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-42599
CVE-2025-36899CVE

CVE-2025-36899

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. …

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-42599
CVE-2025-69902CVE

CVE-2025-69902

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

CVSS 9.8EPSS 2.1%
Match for kev-cve-2025-42599
CVE-2024-56123CVE

CVE-2024-56123

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-42599
CVE-2025-54949CVE

CVE-2025-54949

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493d…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-42599
CVE-2024-56122CVE

CVE-2024-56122

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-42599
CVE-2025-46183CVE

CVE-2025-46183

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintende…

CVSS 8.2EPSS 0.3%
Match for kev-cve-2025-42599
CVE-2025-32595CVE

CVE-2025-32595

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Krowd krowd allows PHP Local File Inclusion.This issue affects Krowd: f…

CVSS 8.1EPSS 0.8%
Match for kev-cve-2025-42599
CVE-2025-65719CVE

CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-42599
CVE-2025-54951CVE

CVE-2025-54951

A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-42599
CVE-2025-49655CVE

CVE-2025-49655

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file containing a TorchMod…

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-42599
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.