Solution sectors / hardware-firmware
Hardware & Firmware
Hardware and firmware vulnerabilities — in BIOS/UEFI, processors, storage and peripherals — sit below the operating system and can persist through reinstalls. This hub tracks CVEs across the hardware layer.
Cumulative CVEs
14,828
across 250 monthly snapshots
Latest month
408 · proj
+10.0% MoM · +135.8% YoY
Peak month
371
Aug 26
KEV this month
0
28 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Embedded75%
- On-prem18%
- Mixed7%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Hardware & Firmware.
- CVE-2026-90891ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control5.5
- CVE-2026-90890ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference5.5
- CVE-2026-33957An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially lea...4.2
- CVE-2026-33964An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited in...6.4
- CVE-2026-31278An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in...7.7
- CVE-2026-90647ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a n...7.4
- CVE-2026-11813A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.7.8
- CVE-2026-18994A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated u...7.1
- CVE-2026-19136A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be execu...7.8
- CVE-2026-63427An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.7.8
- CVE-2026-75940A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.9.1
- CVE-2026-73789Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interface5.3
- CVE-2026-73788Privilege Escalation in ClearPass OnGuard Agent6.5
- CVE-2026-73787Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface7.2
- CVE-2026-73786Unauthenticated Network-Based Denial of Service in CPPM systems7.5
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| hpe | 91 | 6 | · |
| nvidia | 32 | · | · |
| mediatek, inc. | 18 | · | · |
| asus | 12 | · | · |
| arm ltd | 10 | · | · |
| insyde software | 5 | · | · |
| lenovo | 5 | 1 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| — | 62 | 2 | · | 9 | — | aos-cx (34) · arubaos-cx (32) · armoury crate (10) |
| network-adapter | 61 | 15 | · | 6 | — | fabric composer (52) · mt8367 firmware (2) · mt8696 firmware (2) |
| cpu-gpu | 55 | · | · | 7 | — | megatron bridge (30) · nemo megatron bridge (30) · mediatek chipset (18) |
| storage-nas | 14 | 12 | · | 2 | — | powerstore 1000t (13) · powerstore 1200t (13) · powerstore 3000t (13) |
| bios-uefi | 12 | 1 | · | 4 | — | insydeh2o (5) · biostar 2 (1) · control center enterprise (acc) (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification