SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

47 results for “kev-cve-2026-42208” · 1.37 s · cached

Facets · 1 entity types

47 CVE
CVE-2026-41092CVE

CVE-2026-41092

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.3%microsoft
Match for kev-cve-2026-42208
CVE-2026-45760CVE

CVE-2026-45760

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…

CVSS 8.1EPSS 0.4%
Match for kev-cve-2026-42208
CVE-2026-10802CVE

CVE-2026-10802

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL …

CVSS 4.3EPSS 0.3%
Match for kev-cve-2026-42208
CVE-2026-5274CVE

CVE-2026-5274

Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8EPSS 0.3%
Match for kev-cve-2026-42208
CVE-2026-45080CVE

CVE-2026-45080

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in versio…

EPSS 0.4%
Match for kev-cve-2026-42208
CVE-2026-43197CVE

CVE-2026-43197

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to b…

CVSS 9.1EPSS 0.7%linux
Match for kev-cve-2026-42208
CVE-2026-2596CVE

CVE-2026-2596

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-42208
CVE-2026-46207CVE

CVE-2026-46207

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload in tap skb for non-linear buffers For non-linear skbs, virtio_transport_build_skb() goes through …

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-42208
CVE-2026-0029CVE

CVE-2026-0029

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U…

CVSS 8.4EPSS 0.1%
Match for kev-cve-2026-42208
CVE-2026-23204CVE

CVE-2026-23204

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: use skb_header_pointer_careful() skb_header_pointer() does not fully validate negative @offset values. Use s…

CVSS 7.1EPSS 0.1%linux
Match for kev-cve-2026-42208
CVE-2026-6241CVE

CVE-2026-6241

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitizatio…

EPSS 0.3%
Match for kev-cve-2026-42208
CVE-2024-56120CVE

CVE-2024-56120

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2026-42208
CVE-2025-54627CVE

CVE-2025-54627

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 8.8EPSS 0.2%
Match for kev-cve-2026-42208
CVE-2026-46164CVE

CVE-2026-46164

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_sub_group() error path When kobject_init_and_add() fails, the call chain is: create_…

CVSS 7.0EPSS 0.2%linux
Match for kev-cve-2026-42208
CVE-2026-26210CVE

CVE-2026-26210

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authe…

CVSS 9.8EPSS 1.0%kvcache-ai
Match for kev-cve-2026-42208
CVE-2026-41109CVE

CVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…

CVSS 8.8EPSS 0.9%microsoft
Match for kev-cve-2026-42208
CVE-2026-46305CVE

CVE-2026-46305

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc The return value of kzalloc_flex() is used without e…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2026-42208
CVE-2026-46280CVE

CVE-2026-46280

In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to avoid use-after-free Patch series "Minor hmm_test fixes and cleanups". Two bu…

CVSS 7.8EPSS 0.2%linux
Match for kev-cve-2026-42208
CVE-2025-40262CVE

CVE-2025-40262

In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an ad…

CVSS 7.8EPSS 0.1%
Match for kev-cve-2026-42208
CVE-2026-40510CVE

CVE-2026-40510

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trig…

CVSS 3.8EPSS 0.3%opensc_project
Match for kev-cve-2026-42208
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.