SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

29 results for “kev-cve-2025-10035” · 1.48 s · cached

Facets · 1 entity types

29 CVEClear type filter
CVE-2025-1035CVE

CVE-2025-1035

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects…

CVSS 5.7EPSS 9.9%
Match for kev-cve-2025-10035
CVE-2025-49735CVE

CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 1.1%
Match for kev-cve-2025-10035
CVE-2025-33071CVE

CVE-2025-33071

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

CVSS 8.1EPSS 23.2%
Match for kev-cve-2025-10035
CVE-2025-60455CVE

CVE-2025-60455

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

CVSS 8.4EPSS 0.3%
Match for kev-cve-2025-10035
CVE-2025-40252CVE

CVE-2025-40252

In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() The loops in 'qede_tpa_cont()' and 'qede…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2025-10035
CVE-2025-36920CVE

CVE-2025-36920

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2025-10035
CVE-2025-59088CVE

CVE-2025-59088

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. …

CVSS 8.6EPSS 0.5%
Match for kev-cve-2025-10035
CVE-2025-61081CVE

CVE-2025-61081

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Match for kev-cve-2025-10035
CVE-2025-69902CVE

CVE-2025-69902

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

CVSS 9.8EPSS 2.1%
Match for kev-cve-2025-10035
CVE-2026-10238CVE

CVE-2026-10238

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-10035
CVE-2025-10855CVE

CVE-2025-10855

Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identifiers. This issue affects Teknoera: through 01102…

CVSS 7.5EPSS 0.4%
Match for kev-cve-2025-10035
CVE-2025-60228CVE

CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2025-10035
CVE-2025-53578CVE

CVE-2025-53578

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local File Inclusion.This issue affects Kipso: f…

CVSS 8.1EPSS 0.5%
Match for kev-cve-2025-10035
CVE-2026-2575CVE

CVE-2026-2575

A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding.…

CVSS 5.3EPSS 0.7%redhat
Match for kev-cve-2025-10035
CVE-2025-53928CVE

CVE-2025-53928

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the iss…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-10035
CVE-2025-1097CVE

CVE-2025-1097

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This ca…

CVSS 8.8EPSS 33.2%
Match for kev-cve-2025-10035
CVE-2025-40262CVE

CVE-2025-40262

In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an ad…

CVSS 7.8EPSS 0.1%
Match for kev-cve-2025-10035
CVE-2025-32595CVE

CVE-2025-32595

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Krowd krowd allows PHP Local File Inclusion.This issue affects Krowd: f…

CVSS 8.1EPSS 0.8%
Match for kev-cve-2025-10035
CVE-2024-10035CVE

CVE-2024-10035

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an …

CVSS 9.8EPSS 0.8%bg-tek
Match for kev-cve-2025-10035
CVE-2025-4425CVE

CVE-2025-4425

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-10035
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.