SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

40 results for “kev-cve-2025-59374” · 1.44 s · cached

Facets · 1 entity types

40 CVE
CVE-2025-57622CVE

CVE-2025-57622

An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-59374
CVE-2025-1974CVE

CVE-2025-1974

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ing…

CVSS 9.8EPSS 99.4%
Match for kev-cve-2025-59374
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2025-59374
CVE-2025-36920CVE

CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-59374
CVE-2024-56121CVE

CVE-2024-56121

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-59374
CVE-2025-7627CVE

CVE-2025-7627

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file /…

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-59374
CVE-2025-65719CVE

CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-59374
CVE-2025-59823CVE

CVE-2025-59823

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0…

CVSS 9.9EPSS 0.5%
Match for kev-cve-2025-59374
CVE-2025-59461CVE

CVE-2025-59461

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-59374
CVE-2024-56120CVE

CVE-2024-56120

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-59374
CVE-2025-4423CVE

CVE-2025-4423

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-59374
CVE-2025-6573CVE

CVE-2025-6573

Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-59374
CVE-2025-69902CVE

CVE-2025-69902

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

CVSS 9.8EPSS 2.1%
Match for kev-cve-2025-59374
CVE-2025-53578CVE

CVE-2025-53578

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local File Inclusion.This issue affects Kipso: f…

CVSS 8.1EPSS 0.5%
Match for kev-cve-2025-59374
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-59374
CVE-2025-59252CVE

CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 9.3EPSS 0.6%
Match for kev-cve-2025-59374
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-59374
CVE-2025-70420CVE

CVE-2025-70420

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS 0.0%
Match for kev-cve-2025-59374
CVE-2025-0593CVE

CVE-2025-0593

The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.

CVSS 8.8EPSS 0.8%
Match for kev-cve-2025-59374
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for kev-cve-2025-59374
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.