SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

47 results for “kev-cve-2026-41091” · 1.85 s · cached

Facets · 1 entity types

47 CVE
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-41091
CVE-2026-41089CVE

CVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVSS 9.8EPSS 1.0%
Match for kev-cve-2026-41091
CVE-2026-41207CVE

CVE-2026-41207

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distin…

CVSS 5.3EPSS 0.3%netty
Match for kev-cve-2026-41091
CVE-2026-0029CVE

CVE-2026-0029

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2026-41091
CVE-2026-9642CVE

CVE-2026-9642

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS 0.1%
Match for kev-cve-2026-41091
CVE-2026-41109CVE

CVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…

CVSS 8.8EPSS 0.9%microsoft
Match for kev-cve-2026-41091
CVE-2026-4395CVE

CVE-2026-4395

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buff…

CVSS 9.8EPSS 0.6%
Match for kev-cve-2026-41091
CVE-2024-56121CVE

CVE-2024-56121

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-41091
CVE-2026-11091CVE

CVE-2026-11091

Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security s…

CVSS 8.8EPSS 0.2%google
Match for kev-cve-2026-41091
CVE-2025-49091CVE

CVE-2025-49091

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed r…

CVSS 8.2EPSS 0.7%
Match for kev-cve-2026-41091
CVE-2026-10275CVE

CVE-2026-10275

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation …

CVSS 5.0EPSS 0.3%
Match for kev-cve-2026-41091
CVE-2026-46188CVE

CVE-2026-46188

In the Linux kernel, the following vulnerability has been resolved: octeon_ep_vf: add NULL check for napi_build_skb() napi_build_skb() can return NULL on allocation failure. In __octep_vf_oq_proces…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-41091
CVE-2026-9801CVE

CVE-2026-9801

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromi…

CVSS 4.9EPSS 0.9%redhat
Match for kev-cve-2026-41091
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2026-41091
CVE-2026-31611CVE

CVE-2026-31611

In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on m…

CVSS 8.6EPSS 0.5%linux
Match for kev-cve-2026-41091
CVE-2026-31612CVE

CVE-2026-31612

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate EaNameLength in smb2_get_ea() smb2_get_ea() reads ea_req->EaNameLength from the client request and passes it dire…

CVSS 7.5EPSS 0.6%linux
Match for kev-cve-2026-41091
CVE-2026-40401CVE

CVE-2026-40401

Windows TCP/IP Denial of Service Vulnerability

CVSS 7.1EPSS 0.4%microsoft
Match for kev-cve-2026-41091
CVE-2026-28027CVE

CVE-2026-28027

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Kayon kayon allows PHP Local File Inclusion.This issue affects Kayon:…

CVSS 8.1EPSS 0.6%
Match for kev-cve-2026-41091
CVE-2026-11460CVE

CVE-2026-11460

A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initia…

CVSS 7.3EPSS 0.3%
Match for kev-cve-2026-41091
CVE-2026-4366CVE

CVE-2026-4366

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows a…

CVSS 5.8EPSS 0.4%redhat
Match for kev-cve-2026-41091
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.