SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

32 results for “kev-cve-2025-24989” · 1.90 s · cached

Facets · 1 entity types

32 CVE
CVE-2025-24956CVE

CVE-2025-24956

A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-24989
CVE-2025-24983CVE

Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 1.4%KEVMicrosoft
Match for kev-cve-2025-24989
CVE-2025-24922CVE

CVE-2025-24922

A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially craf…

CVSS 8.8EPSS 3.4%
Match for kev-cve-2025-24989
CVE-2025-54949CVE

CVE-2025-54949

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493d…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-24989
CVE-2025-24936CVE

CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attac…

CVSS 9.0EPSS 0.4%
Match for kev-cve-2025-24989
CVE-2025-29922CVE

CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object vi…

CVSS 9.6EPSS 0.4%
Match for kev-cve-2025-24989
CVE-2026-4789CVE

CVE-2026-4789

Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-24989
CVE-2025-54951CVE

CVE-2025-54951

A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-24989
CVE-2026-49510CVE

CVE-2026-49510

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.

CVSS 6.1EPSS 0.1%
Match for kev-cve-2025-24989
CVE-2025-4422CVE

CVE-2025-4422

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-24989
CVE-2026-45839CVE

CVE-2026-45839

In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE accessor strings are colon-separated indices that desc…

CVSS 7.8EPSS 0.2%linux
Match for kev-cve-2025-24989
CVE-2025-49212CVE

CVE-2025-49212

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerabil…

CVSS 9.8EPSS 13.3%
Match for kev-cve-2025-24989
CVE-2025-24919CVE

CVE-2025-24919

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially craft…

CVSS 8.1EPSS 2.6%
Match for kev-cve-2025-24989
CVE-2025-4425CVE

CVE-2025-4425

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-24989
CVE-2024-49925CVE

CVE-2024-49925

In the Linux kernel, the following vulnerability has been resolved: fbdev: efifb: Register sysfs groups through driver core The driver core can register and cleanup sysfs groups already. Make use o…

CVSS 7.1EPSS 0.3%linux
Match for kev-cve-2025-24989
CVE-2025-4423CVE

CVE-2025-4423

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.2%
Match for kev-cve-2025-24989
CVE-2026-50265CVE

CVE-2026-50265

Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292

EPSS 0.0%
Match for kev-cve-2025-24989
CVE-2025-20949CVE

CVE-2025-20949

Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.

CVSS 9.1EPSS 0.3%
Match for kev-cve-2025-24989
CVE-2026-42914CVE

CVE-2026-42914

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVSS 5.3EPSS 0.8%microsoft
Match for kev-cve-2025-24989
CVE-2026-44988CVE

CVE-2026-44988

LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but…

CVSS 8.8EPSS 0.4%
Match for kev-cve-2025-24989
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.