SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

37 results for “kev-cve-2026-45498” · 1.26 s · cached

Facets · 1 entity types

37 CVE
CVE-2026-45497CVE

CVE-2026-45497

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

CVSS 7.7EPSS 0.6%microsoft
Match for kev-cve-2026-45498
CVE-2026-45446CVE

CVE-2026-45446

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of …

CVSS 4.8EPSS 0.2%openssl
Match for kev-cve-2026-45498
CVE-2026-45447CVE

CVE-2026-45447

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes…

CVSS 8.8EPSS 4.0%openssl
Match for kev-cve-2026-45498
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-45498
CVE-2026-45495CVE

CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS 9.8EPSS 1.0%
Match for kev-cve-2026-45498
CVE-2026-5434CVE

CVE-2026-5434

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially…

CVSS 5.9EPSS 0.3%
Match for kev-cve-2026-45498
CVE-2026-40527CVE

CVE-2026-40527

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_pa…

CVSS 7.8EPSS 1.5%radare
Match for kev-cve-2026-45498
CVE-2026-45838CVE

CVE-2026-45838

In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_get_next_key() list_next_entry() never returns NULL -- when the current element …

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-45498
CVE-2024-56122CVE

CVE-2024-56122

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-45498
CVE-2026-44697CVE

CVE-2026-44697

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any p…

CVSS 8.6EPSS 0.5%
Match for kev-cve-2026-45498
CVE-2026-45490CVE

CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.4%microsoft
Match for kev-cve-2026-45498
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2026-45498
CVE-2026-45482CVE

CVE-2026-45482

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVSS 8.4EPSS 0.4%microsoft
Match for kev-cve-2026-45498
CVE-2026-45491CVE

CVE-2026-45491

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

CVSS 6.2EPSS 0.4%microsoft
Match for kev-cve-2026-45498
CVE-2026-46082CVE

CVE-2026-46082

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inj…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-45498
CVE-2026-45474CVE

CVE-2026-45474

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS 8.4EPSS 0.4%microsoft
Match for kev-cve-2026-45498
CVE-2024-56120CVE

CVE-2024-56120

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-45498
CVE-2026-45592CVE

CVE-2026-45592

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for kev-cve-2026-45498
CVE-2024-56123CVE

CVE-2024-56123

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-45498
CVE-2024-56121CVE

CVE-2024-56121

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-45498
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.