SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

42 results for “kev-cve-2025-49706” · 2.14 s · cached

Facets · 1 entity types

42 CVE
CVE-2025-70420CVE

CVE-2025-70420

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS 0.0%
Match for kev-cve-2025-49706
CVE-2025-49091CVE

CVE-2025-49091

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed r…

CVSS 8.2EPSS 0.7%
Match for kev-cve-2025-49706
CVE-2025-27060CVE

CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

CVSS 8.8EPSS 0.1%
Match for kev-cve-2025-49706
CVE-2025-59604CVE

CVE-2025-59604

Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2025-49706
CVE-2025-4422CVE

CVE-2025-4422

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-49706
CVE-2024-56123CVE

CVE-2024-56123

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-49706
CVE-2026-4821CVE

CVE-2026-4821

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error.

Match for kev-cve-2025-49706
CVE-2025-4421CVE

CVE-2025-4421

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.3%
Match for kev-cve-2025-49706
CVE-2026-9642CVE

CVE-2026-9642

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS 0.1%
Match for kev-cve-2025-49706
CVE-2026-40685CVE

CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-49706
CVE-2026-6208CVE

CVE-2026-6208

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-49706
CVE-2025-46183CVE

CVE-2025-46183

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in unintende…

CVSS 8.2EPSS 0.3%
Match for kev-cve-2025-49706
CVE-2026-6209CVE

CVE-2026-6209

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-49706
CVE-2026-44697CVE

CVE-2026-44697

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any p…

CVSS 8.6EPSS 0.5%
Match for kev-cve-2025-49706
CVE-2026-5434CVE

CVE-2026-5434

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially…

CVSS 5.9EPSS 0.3%
Match for kev-cve-2025-49706
CVE-2025-59088CVE

CVE-2025-59088

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. …

CVSS 8.6EPSS 0.5%
Match for kev-cve-2025-49706
CVE-2025-53606CVE

CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-49706
CVE-2025-69902CVE

CVE-2025-69902

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

CVSS 9.8EPSS 2.1%
Match for kev-cve-2025-49706
CVE-2026-0029CVE

CVE-2026-0029

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-49706
CVE-2025-68706CVE

CVE-2025-68706

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-suppli…

CVSS 9.8EPSS 5.0%
Match for kev-cve-2025-49706
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.