SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

33 results for “kev-cve-2025-24991” · 0.95 s · cached

Facets · 1 entity types

33 CVE
CVE-2025-24956CVE

CVE-2025-24956

A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a…

CVSS 9.8EPSS 0.4%
Match for kev-cve-2025-24991
CVE-2025-29922CVE

CVE-2025-29922

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.26.3, the identified vulnerability allows creating or deleting an object vi…

CVSS 9.6EPSS 0.4%
Match for kev-cve-2025-24991
CVE-2025-54951CVE

CVE-2025-54951

A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-24991
CVE-2025-49212CVE

CVE-2025-49212

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerabil…

CVSS 9.8EPSS 13.3%
Match for kev-cve-2025-24991
CVE-2026-4821CVE

CVE-2026-4821

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error.

Match for kev-cve-2025-24991
CVE-2026-46291CVE

CVE-2026-46291

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - guard HMAC key hex dumps in hash_digest_key Use print_hex_dump_devel() for dumping sensitive HMAC key bytes in has…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-24991
CVE-2025-29778CVE

CVE-2025-29778

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with k…

CVSS 8.0EPSS 0.3%
Match for kev-cve-2025-24991
CVE-2025-24936CVE

CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attac…

CVSS 9.0EPSS 0.4%
Match for kev-cve-2025-24991
CVE-2026-4747CVE

CVE-2026-4747

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is …

CVSS 8.8EPSS 1.1%
Match for kev-cve-2025-24991
CVE-2025-4421CVE

CVE-2025-4421

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information about the vulnerabilit…

CVSS 8.2EPSS 0.3%
Match for kev-cve-2025-24991
CVE-2025-22041CVE

CVE-2025-22041

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can occur in session_deregister when the…

CVSS 8.8EPSS 0.7%
Match for kev-cve-2025-24991
CVE-2025-23181CVE

CVE-2025-23181

CWE-250: Execution with Unnecessary Privileges

CVSS 8.0EPSS 0.3%
Match for kev-cve-2025-24991
CVE-2026-45839CVE

CVE-2026-45839

In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() CO-RE accessor strings are colon-separated indices that desc…

CVSS 7.8EPSS 0.2%linux
Match for kev-cve-2025-24991
CVE-2025-49091CVE

CVE-2025-49091

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed r…

CVSS 8.2EPSS 0.7%
Match for kev-cve-2025-24991
CVE-2025-24861CVE

CVE-2025-24861

An attacker may inject commands via specially-crafted post requests.

CVSS 9.8EPSS 0.5%
Match for kev-cve-2025-24991
CVE-2026-50265CVE

CVE-2026-50265

Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292

EPSS 0.0%
Match for kev-cve-2025-24991
CVE-2025-26597CVE

CVE-2025-26597

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same f…

CVSS 7.8EPSS 0.4%tigervnc
Match for kev-cve-2025-24991
CVE-2025-24983CVE

Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 1.4%KEVMicrosoft
Match for kev-cve-2025-24991
CVE-2025-54949CVE

CVE-2025-54949

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493d…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2025-24991
CVE-2022-49961CVE

CVE-2022-49961

In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CON…

CVSS 7.1EPSS 0.3%linux
Match for kev-cve-2025-24991
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.