SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

43 results for “kev-cve-2026-3502” · 0.87 s · cached

Facets · 1 entity types

43 CVE
CVE-2026-26030CVE

CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The…

CVSS 9.9EPSS 3.7%
Match for kev-cve-2026-3502
CVE-2026-10802CVE

CVE-2026-10802

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL …

CVSS 4.3EPSS 0.3%
Match for kev-cve-2026-3502
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2026-3502
CVE-2026-10814CVE

CVE-2026-10814

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Han…

CVSS 4.5EPSS 0.1%milvus
Match for kev-cve-2026-3502
CVE-2025-60228CVE

CVE-2025-60228

Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9.

CVSS 8.8EPSS 0.5%
Match for kev-cve-2026-3502
CVE-2026-44009CVE

CVE-2026-44009

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

CVSS 9.8EPSS 0.7%vm2_project
Match for kev-cve-2026-3502
CVE-2026-25360CVE

CVE-2026-25360

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

CVSS 8.8EPSS 0.3%
Match for kev-cve-2026-3502
CVE-2026-25260CVE

CVE-2026-25260

Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

CVSS 7.8EPSS 0.1%qualcomm
Match for kev-cve-2026-3502
CVE-2026-5503CVE

CVE-2026-5503

In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This caused TLSX_UseSNI to attach the attacker-controlled publicName to the shared W…

CVSS 9.1EPSS 0.5%
Match for kev-cve-2026-3502
CVE-2026-4821CVE

CVE-2026-4821

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error.

Match for kev-cve-2026-3502
CVE-2026-22039CVE

CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall…

CVSS 9.9EPSS 0.6%
Match for kev-cve-2026-3502
CVE-2026-40403CVE

CVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

CVSS 8.8EPSS 0.3%
Match for kev-cve-2026-3502
CVE-2026-31636CVE

CVE-2026-31636

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and t…

CVSS 9.1EPSS 0.6%
Match for kev-cve-2026-3502
CVE-2026-9642CVE

CVE-2026-9642

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS 0.1%
Match for kev-cve-2026-3502
CVE-2026-35167CVE

CVE-2026-35167

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version …

CVSS 8.1EPSS 0.4%
Match for kev-cve-2026-3502
CVE-2026-46264CVE

CVE-2026-46264

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failure the provided cleanup action will be run immedia…

CVSS 8.8EPSS 0.2%linux
Match for kev-cve-2026-3502
CVE-2026-43331CVE

CVE-2026-43331

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments() function changes segment registers, invalidatin…

CVSS 5.5EPSS 0.1%linux
Match for kev-cve-2026-3502
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-3502
CVE-2026-43304CVE

CVE-2026-43304

In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buff…

CVSS 9.8EPSS 0.7%
Match for kev-cve-2026-3502
CVE-2026-26210CVE

CVE-2026-26210

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authe…

CVSS 9.8EPSS 1.0%kvcache-ai
Match for kev-cve-2026-3502
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.