SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

13 results for “kev-cve-2018-18325” · 0.85 s · cached

Facets · 1 entity types

13 CVE
CVE-2025-66518CVE

CVE-2025-66518

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the confi…

CVSS 8.8EPSS 1.0%apache
Match for kev-cve-2018-18325
CVE-2026-1819CVE

CVE-2026-1819

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS. This issue affects Vi…

CVSS 8.8EPSS 0.4%
Match for kev-cve-2018-18325
CVE-2025-65719CVE

CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8EPSS 0.6%
Match for kev-cve-2018-18325
CVE-2025-31183CVE

CVE-2025-31183

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app m…

CVSS 9.8EPSS 1.2%
Match for kev-cve-2018-18325
CVE-2025-11960CVE

CVE-2025-11960

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS. This issue affec…

CVSS 6.1EPSS 0.2%
Match for kev-cve-2018-18325
CVE-2025-69902CVE

CVE-2025-69902

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

CVSS 9.8EPSS 2.1%
Match for kev-cve-2018-18325
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2018-18325
CVE-2025-60228CVE

CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2018-18325
CVE-2025-31234CVE

CVE-2025-31234

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An attacker may be able to cause unexpected sys…

CVSS 8.2EPSS 0.6%
Match for kev-cve-2018-18325
CVE-2026-43185CVE

CVE-2026-43185

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value fr…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2018-18325
CVE-2025-10318CVE

CVE-2025-10318

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler…

CVSS 8.8EPSS 0.4%
Match for kev-cve-2018-18325
CVE-2025-24178CVE

CVE-2025-24178

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, w…

CVSS 9.8EPSS 1.6%
Match for kev-cve-2018-18325
CVE-2025-56122CVE

CVE-2025-56122

OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/l…

CVSS 8.8EPSS 2.6%
Match for kev-cve-2018-18325
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.