SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

24 results for “kev-cve-2015-2502” · 1.68 s · cached

Facets · 1 entity types

24 CVEClear type filter
CVE-2025-60228CVE

CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2015-2502
CVE-2025-60455CVE

CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

CVSS 8.4EPSS 0.3%
Match for kev-cve-2015-2502
CVE-2026-40528CVE

CVE-2026-40528

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memor…

CVSS 3.8EPSS 0.2%opensc_project
Match for kev-cve-2015-2502
CVE-2026-31590CVE

CVE-2026-31590

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION Drop the WARN in sev_pin_memory() on npages overflowing an in…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2015-2502
CVE-2025-40252CVE

CVE-2025-40252

In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2015-2502
CVE-2026-25210CVE

CVE-2026-25210

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

CVSS 6.9EPSS 0.2%libexpat_project
Match for kev-cve-2015-2502
CVE-2025-60215CVE

CVE-2025-60215

Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2015-2502
CVE-2025-24260CVE

CVE-2025-24260

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perfor…

CVSS 9.8EPSS 0.9%
Match for kev-cve-2015-2502
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2015-2502
CVE-2026-50265CVE

CVE-2026-50265

Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292

EPSS 0.0%
Match for kev-cve-2015-2502
CVE-2025-61081CVE

CVE-2025-61081

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Match for kev-cve-2015-2502
CVE-2025-40263CVE

CVE-2025-40263

In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`…

EPSS 0.2%
Match for kev-cve-2015-2502
CVE-2026-25029CVE

CVE-2026-25029

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

CVSS 9.8EPSS 0.4%
Match for kev-cve-2015-2502
CVE-2025-49735CVE

CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 1.1%
Match for kev-cve-2015-2502
CVE-2025-30452CVE

CVE-2025-30452

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An input validation issue was addressed.

CVSS 9.8EPSS 1.1%
Match for kev-cve-2015-2502
CVE-2025-49091CVE

CVE-2025-49091

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed r…

CVSS 8.2EPSS 0.7%
Match for kev-cve-2015-2502
CVE-2026-24515CVE

CVE-2026-24515

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

CVSS 2.9EPSS 0.2%libexpat_project
Match for kev-cve-2015-2502
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2015-2502
CVE-2025-40262CVE

CVE-2025-40262

In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an ad…

CVSS 7.8EPSS 0.1%
Match for kev-cve-2015-2502
CVE-2025-55050CVE

CVE-2025-55050

CWE-1242: Inclusion of Undocumented Features

CVSS 9.8EPSS 0.3%
Match for kev-cve-2015-2502
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.