SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

38 results for “kev-cve-2025-53770” · 2.44 s · cached

Facets · 1 entity types

38 CVE
CVE-2025-59377CVE

CVE-2025-59377

feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOTE: this is unrelated to mcp-server-kubernetes and CV…

CVSS 9.8EPSS 1.2%
Match for kev-cve-2025-53770
CVE-2025-34070CVE

CVE-2025-34070

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible…

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-53770
CVE-2025-65719CVE

CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-53770
CVE-2025-59382CVE

CVE-2025-59382

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

EPSS 0.4%
Match for kev-cve-2025-53770
CVE-2025-4423CVE

CVE-2025-4423

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-53770
CVE-2025-66276CVE

CVE-2025-66276

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

CVSS 9.8EPSS 0.3%qnap
Match for kev-cve-2025-53770
CVE-2025-34071CVE

CVE-2025-34071

A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgr…

CVSS 9.8EPSS 0.8%
Match for kev-cve-2025-53770
CVE-2026-6207CVE

CVE-2026-6207

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-53770
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-53770
CVE-2025-27059CVE

CVE-2025-27059

Memory corruption while performing SCM call.

CVSS 8.8EPSS 0.1%qualcomm
Match for kev-cve-2025-53770
CVE-2025-55232CVE

CVE-2025-55232

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

CVSS 9.8EPSS 2.1%
Match for kev-cve-2025-53770
CVE-2025-5253CVE

CVE-2025-5253

Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS. This issue affects Kron PAM: before 3.7.

CVSS 6.5EPSS 0.4%
Match for kev-cve-2025-53770
CVE-2025-27060CVE

CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

CVSS 8.8EPSS 0.1%
Match for kev-cve-2025-53770
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-53770
CVE-2025-5978CVE

CVE-2025-5978

A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page l…

CVSS 8.8EPSS 1.0%
Match for kev-cve-2025-53770
CVE-2025-25723CVE

CVE-2025-25723

Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

CVSS 8.4EPSS 0.4%
Match for kev-cve-2025-53770
CVE-2025-5387CVE

CVE-2025-5387

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The ma…

CVSS 9.8EPSS 0.3%
Match for kev-cve-2025-53770
CVE-2025-59605CVE

CVE-2025-59605

Memory Corruption when processing device identifier strings that exceed the expected maximum length.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2025-53770
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.