Solution sectors / hardware-firmware
Hardware & Firmware
Hardware and firmware vulnerabilities — in BIOS/UEFI, processors, storage and peripherals — sit below the operating system and can persist through reinstalls. This hub tracks CVEs across the hardware layer.
Cumulative CVEs
14,225
across 248 monthly snapshots
Latest month
146 · proj
-21.5% MoM · -12.0% YoY
Peak month
327
May 23
KEV this month
0
23 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem48%
- Embedded38%
- Mixed14%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Hardware & Firmware.
- CVE-2026-49745GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 07.8
- CVE-2026-49744GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()7.8
- CVE-2026-49743GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed7.8
- CVE-2026-16606Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris9.8
- CVE-2026-16607Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris7.8
- CVE-2026-44879Authenticated Command Injection allows arbitrary command execution in CLI Interface7.2
- CVE-2026-44878Authenticated Path Traversal allows Unauthorized Access in Web Interface7.2
- CVE-2026-63454Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX7.2
- CVE-2026-63453Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX7.2
- CVE-2026-44880Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX8.8
- CVE-2026-24232NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, da...4.3
- CVE-2019-25764**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resu...7.0
- CVE-2026-10590A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.4.4
- CVE-2026-10589A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.6.0
- CVE-2026-10588A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.4.4
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| nvidia | 40 | 3 | · |
| asus | 12 | · | · |
| qualcomm | 11 | · | · |
| lenovo | 9 | · | · |
| mediatek, inc. | 7 | · | · |
| imagination technologies | 5 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| — | 68 | 18 | · | 8 | — | tensorrt-llm (12) · fastconnect 6900 firmware (11) · fastconnect 7800 firmware (11) |
| cpu-gpu | 27 | 1 | · | 6 | — | nemo megatron bridge (11) · mediatek chipset (7) · graphics ddk (5) |
| bios-uefi | 24 | · | · | 3 | — | wcd9380 firmware (11) · wsa8830 firmware (10) · wsa8835 firmware (10) |
| printer-peripheral | 5 | 4 | · | 4 | — | ma-t6 (2) · ma-t6 kohinoor spectrophotometer (2) · alienware m16 r2 (1) |
| network-adapter | 3 | 1 | · | 2 | — | cf-wr631ax v3 (1) · digi one ia (1) · digi one sp (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification