6.4

CVSS3.1

CVE-2026-21265 - Secure Boot Certificate Expiration Security Feature Bypass Vulnerability

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes relaโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 5:56 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:30 p.m.

4.4

CVSS3.1

CVE-2026-20962 - Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

๐Ÿ“… Published: Jan. 13, 2026, 5:56 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:30 p.m.

7.5

CVSS3.1

CVE-2025-37166 - Unexpected shutdown in HPE Instant On Access Points after processing specific packets

A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conducโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 5:42 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-37165 - Exposure of VLAN information in unintended network interfaces

A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.

๐Ÿ“… Published: Jan. 13, 2026, 5:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-10865 - GPU DDK - DevmemIntGetReservationData does not ref the PMR it returns

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was present.

๐Ÿ“… Published: Jan. 13, 2026, 5:26 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 6:39 p.m.

8.8

CVSS3.1

CVE-2025-58411 - GPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAF

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potentialโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 4:41 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 6:38 p.m.

3.5

CVSS3.1

CVE-2025-58409 - GPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical meโ€ฆ

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kerneโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 4:37 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 6:39 p.m.

5.3

CVSS4.0

CVE-2025-62182 - Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file uโ€ฆ

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.

๐Ÿ“… Published: Jan. 13, 2026, 4:37 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-46685 -

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

๐Ÿ“… Published: Jan. 13, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

6.2

CVSS3.1

CVE-2025-8090 - Vulnerability in the QNX Neutrino Kernel impacts the QNX Software Development Platform and QNX OS fโ€ฆ

Null pointer dereference in the MsgRegisterEvent() system call could allowย an attacker with local access and code execution abilities to crash theย QNX Neutrino kernel.

๐Ÿ“… Published: Jan. 13, 2026, 4:36 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345149
Page 1767 of 34,515
ยซ previous page ยป next page
Filters