Solution sectors / hardware-firmware
Hardware & Firmware
Hardware and firmware vulnerabilities — in BIOS/UEFI, processors, storage and peripherals — sit below the operating system and can persist through reinstalls. This hub tracks CVEs across the hardware layer.
Cumulative CVEs
14,355
across 249 monthly snapshots
Latest month
264 · proj
+70.3% MoM · +10.0% YoY
Peak month
327
May 23
KEV this month
0
22 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Embedded79%
- On-prem18%
- Mixed3%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Hardware & Firmware.
- CVE-2026-6484Lack of verified boot to certain FV may cause arbitrary code execution8.2
- CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/file7.5
- CVE-2026-19381Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management7.8
- CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection7.3
- CVE-2026-19192DeepCool DisplayService DeepCoolDisplayService.exe access control7.8
- CVE-2026-49746GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem7.1
- CVE-2026-45204GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory5.5
- CVE-2026-45198GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted7.8
- CVE-2026-63457A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.6.5
- CVE-2026-16793Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator8.8
- CVE-2026-16792Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator6.1
- CVE-2026-16791Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI3.9
- CVE-2026-49435Keysight IxChariot-related products stack-based buffer overflow9.8
- CVE-2017-20242Keysight IxChariot Endpoint stack-based buffer overflow9.8
- CVE-2017-20241Keysight IxChariot Endpoint heap-based buffer overflow9.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| mediatek, inc. | 34 | · | · |
| nvidia | 16 | 1 | · |
| qualcomm | 11 | 1 | · |
| unisoc (shanghai) technologies co., ltd. | 8 | · | · |
| sharp corporation | 4 | · | · |
| hpe | 3 | 2 | · |
| imagination technologies | 3 | · | · |
| keysight | 3 | 3 | · |
| lenovo | 3 | · | · |
| toshiba tec corporation | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| cpu-gpu | 62 | 1 | · | 5 | — | mediatek chipset (34) · dynamo (15) · t8100/t9100/t8200/t8300 (6) |
| — | 17 | 201 | · | 6 | — | snapdragon (11) · fastconnect 6900 firmware (9) · fastconnect 7800 firmware (9) |
| bios-uefi | 9 | 3 | · | 2 | — | wcd9380 firmware (8) · wsa8830 firmware (7) · wsa8835 firmware (7) |
| printer-peripheral | 7 | · | · | 4 | — | sharp mfps (3) · toshiba tec mfps (3) · display and peripheral manager (2) |
| network-adapter | 5 | 7 | · | 3 | — | ixchariot (3) · hawkeye (1) · hpe integrated lights-out 6 (ilo 6) (1) |
| storage-nas | 2 | · | · | 2 | — | abp (1) · aes (1) · fury ctrl rgb control software (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification