SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

42 results for “kev-cve-2025-54236” · 0.53 s · cached

Facets · 1 entity types

42 CVE
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for kev-cve-2025-54236
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-54236
CVE-2026-45838CVE

CVE-2026-45838

In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_get_next_key() list_next_entry() never returns NULL -- when the current element …

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-54236
CVE-2026-25258CVE

CVE-2026-25258

Memory corruption while processing IOCTL calls for escape operations.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2025-54236
CVE-2025-59088CVE

CVE-2025-59088

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. …

CVSS 8.6EPSS 0.5%
Match for kev-cve-2025-54236
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-54236
CVE-2025-24260CVE

CVE-2025-24260

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perfor…

CVSS 9.8EPSS 0.9%
Match for kev-cve-2025-54236
CVE-2025-59605CVE

CVE-2025-59605

Memory Corruption when processing device identifier strings that exceed the expected maximum length.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2025-54236
CVE-2025-57622CVE

CVE-2025-57622

An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-54236
CVE-2025-52562CVE

CVE-2025-52562

Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController component of Performave Con…

CVSS 10.0EPSS 1.8%
Match for kev-cve-2025-54236
CVE-2025-65719CVE

CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-54236
CVE-2026-50265CVE

CVE-2026-50265

Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292

EPSS 0.0%
Match for kev-cve-2025-54236
CVE-2025-27060CVE

CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

CVSS 8.8EPSS 0.1%
Match for kev-cve-2025-54236
CVE-2025-40252CVE

CVE-2025-40252

In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-54236
CVE-2026-25259CVE

CVE-2026-25259

Memory corruption while processing multiple IOCTL command for escape operations.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2025-54236
CVE-2025-54617CVE

CVE-2025-54617

Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

CVSS 9.8EPSS 0.3%
Match for kev-cve-2025-54236
CVE-2025-25723CVE

CVE-2025-25723

Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

CVSS 8.4EPSS 0.4%
Match for kev-cve-2025-54236
CVE-2026-10238CVE

CVE-2026-10238

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-54236
CVE-2025-31234CVE

CVE-2025-31234

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An attacker may be able to cause unexpected sys…

CVSS 8.2EPSS 0.6%
Match for kev-cve-2025-54236
CVE-2025-1035CVE

CVE-2025-1035

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects…

CVSS 5.7EPSS 9.9%
Match for kev-cve-2025-54236
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.