SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

41 results for “kev-cve-2025-54253” · 1.25 s · cached

Facets · 1 entity types

41 CVE
CVE-2024-56123CVE

CVE-2024-56123

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-54253
CVE-2025-54322CVE

CVE-2025-54322

Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

CVSS 10.0EPSS 15.1%xspeeder
Match for kev-cve-2025-54253
CVE-2025-8653CVE

CVE-2025-8653

Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatio…

CVSS 8.8EPSS 0.3%
Match for kev-cve-2025-54253
CVE-2026-31553CVE

CVE-2026-31553

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2025-54253
CVE-2024-56121CVE

CVE-2024-56121

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-54253
CVE-2025-52562CVE

CVE-2025-52562

Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController component of Performave Con…

CVSS 10.0EPSS 1.8%
Match for kev-cve-2025-54253
CVE-2025-59272CVE

CVE-2025-59272

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

CVSS 9.3EPSS 0.6%
Match for kev-cve-2025-54253
CVE-2025-40252CVE

CVE-2025-40252

In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-54253
CVE-2025-58455CVE

CVE-2025-58455

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code vi…

CVSS 8.0EPSS 0.5%
Match for kev-cve-2025-54253
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-54253
CVE-2025-5254CVE

CVE-2025-5254

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS. This issue affects Kron PAM: before 3.7.

CVSS 6.1EPSS 0.4%
Match for kev-cve-2025-54253
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-54253
CVE-2025-8654CVE

CVE-2025-8654

Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwoo…

CVSS 8.8EPSS 0.8%
Match for kev-cve-2025-54253
CVE-2025-59252CVE

CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 9.3EPSS 0.6%
Match for kev-cve-2025-54253
CVE-2025-54949CVE

CVE-2025-54949

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493d…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-54253
CVE-2025-54617CVE

CVE-2025-54617

Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

CVSS 9.8EPSS 0.3%
Match for kev-cve-2025-54253
CVE-2025-54952CVE

CVE-2025-54952

An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effe…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-54253
CVE-2025-43275CVE

CVE-2025-43275

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-54253
CVE-2025-59382CVE

CVE-2025-59382

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

EPSS 0.4%
Match for kev-cve-2025-54253
CVE-2025-62405CVE

CVE-2025-62405

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code vi…

CVSS 8.0EPSS 0.5%
Match for kev-cve-2025-54253
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.