SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

23 results for “kev-cve-2023-24955” · 2.24 s · cached

Facets · 1 entity types

23 CVEClear type filter
CVE-2025-24956CVE

CVE-2025-24956

A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2023-24955
CVE-2025-29922CVE

CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object vi…

CVSS 9.6EPSS 0.4%
Match for kev-cve-2023-24955
CVE-2026-34940CVE

CVE-2026-34940

KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/modelcontroller/engine_ollama.go constructs a shell command string using fmt.Sp…

CVSS 8.8EPSS 0.5%
Match for kev-cve-2023-24955
CVE-2025-24922CVE

CVE-2025-24922

A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially craf…

CVSS 8.8EPSS 3.4%
Match for kev-cve-2023-24955
CVE-2025-24919CVE

CVE-2025-24919

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially craft…

CVSS 8.1EPSS 2.6%
Match for kev-cve-2023-24955
CVE-2025-24936CVE

CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attac…

CVSS 9.0EPSS 0.4%
Match for kev-cve-2023-24955
CVE-2022-50552CVE

CVE-2022-50552

In the Linux kernel, the following vulnerability has been resolved: blk-mq: use quiesced elevator switch when reinitializing queues The hctx's run_work may be racing with the elevator switch when r…

CVSS 7.8EPSS 0.2%linux
Match for kev-cve-2023-24955
CVE-2026-39429CVE

CVE-2026-39429

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and…

CVSS 8.2EPSS 0.5%kcp
Match for kev-cve-2023-24955
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2023-24955
CVE-2026-23455CVE

CVE-2026-23455

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit leng…

CVSS 9.1EPSS 1.3%linux
Match for kev-cve-2023-24955
CVE-2026-45446CVE

CVE-2026-45446

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of …

CVSS 4.8EPSS 0.2%openssl
Match for kev-cve-2023-24955
CVE-2022-50493CVE

CVE-2022-50493

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call …

CVSS 8.8EPSS 0.2%linux
Match for kev-cve-2023-24955
CVE-2025-24983CVE

Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 1.4%KEVMicrosoft
Match for kev-cve-2023-24955
CVE-2025-29778CVE

CVE-2025-29778

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with k…

CVSS 8.0EPSS 0.3%
Match for kev-cve-2023-24955
CVE-2026-22039CVE

CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall…

CVSS 9.9EPSS 0.6%
Match for kev-cve-2023-24955
CVE-2026-24515CVE

CVE-2026-24515

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

CVSS 2.9EPSS 0.2%libexpat_project
Match for kev-cve-2023-24955
CVE-2026-29955CVE

CVE-2026-29955

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute sh…

CVSS 8.8EPSS 2.9%
Match for kev-cve-2023-24955
CVE-2026-40685CVE

CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2023-24955
CVE-2025-60455CVE

CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

CVSS 8.4EPSS 0.3%
Match for kev-cve-2023-24955
CVE-2025-24514CVE

CVE-2025-24514

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to…

CVSS 8.8EPSS 30.5%
Match for kev-cve-2023-24955
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.