SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

38 results for “kev-cve-2026-33634” · 1.01 s · cached

Facets · 1 entity types

38 CVE
CVE-2026-43331CVE

CVE-2026-43331

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments() function changes segment registers, invalidatin…

CVSS 5.5EPSS 0.1%linux
Match for kev-cve-2026-33634
CVE-2026-31553CVE

CVE-2026-31553

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2026-33634
CVE-2026-38428CVE

CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitiza…

CVSS 9.8EPSS 0.5%kestra
Match for kev-cve-2026-33634
CVE-2026-23456CVE

CVE-2026-23456

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read…

CVSS 8.2EPSS 0.5%linux
Match for kev-cve-2026-33634
CVE-2026-43406CVE

CVE-2026-43406

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a w…

CVSS 9.1EPSS 0.7%
Match for kev-cve-2026-33634
CVE-2026-33634CVE

Aquasecurity Trivy Embedded Malicious Code Vulnerability

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credenti…

CVSS 8.8EPSS 1.7%KEVAquasecurity
Match for kev-cve-2026-33634
CVE-2026-23112CVE

CVE-2026-23112

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU leng…

CVSS 9.8EPSS 0.4%linux
Match for kev-cve-2026-33634
CVE-2026-35433CVE

CVE-2026-35433

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

CVSS 7.3EPSS 0.6%microsoft
Match for kev-cve-2026-33634
CVE-2026-34612CVE

CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Exec…

CVSS 9.9EPSS 0.7%kestra
Match for kev-cve-2026-33634
CVE-2026-31590CVE

CVE-2026-31590

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION Drop the WARN in sev_pin_memory() on npages overflowing an in…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-33634
CVE-2026-33833CVE

CVE-2026-33833

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

CVSS 8.2EPSS 0.5%microsoft
Match for kev-cve-2026-33634
CVE-2026-31558CVE

CVE-2026-31558

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so cp…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2026-33634
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-33634
CVE-2026-23455CVE

CVE-2026-23455

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit leng…

CVSS 9.1EPSS 1.3%linux
Match for kev-cve-2026-33634
CVE-2026-5434CVE

CVE-2026-5434

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially…

CVSS 5.9EPSS 0.3%
Match for kev-cve-2026-33634
CVE-2026-31634CVE

CVE-2026-31634

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix reference count leak in rxrpc_server_keyring() This patch fixes a reference count leak in rxrpc_server_keyring() by ch…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-33634
CVE-2026-34336CVE

CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for kev-cve-2026-33634
CVE-2026-31432CVE

CVE-2026-31432

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as READ + QUERY_INFO(Security) is received,…

CVSS 8.8EPSS 0.6%linux
Match for kev-cve-2026-33634
CVE-2026-46237CVE

CVE-2026-46237

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS 0.0%
Match for kev-cve-2026-33634
CVE-2026-31636CVE

CVE-2026-31636

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and t…

CVSS 9.1EPSS 0.6%
Match for kev-cve-2026-33634
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.