Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-4277

Tcg2Smm: improper input validation may lead to arbitrary code execution_CVE-2025-4277

Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

Insyde Software InsydeH2O Kernel 5.2 CVE
HIGH 7.5 CVE-2025-4276

UsbCoreDxe: improper input validation may lead to arbitrary code execution_CVE-2025-4276

UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

Insyde Software InsydeH2O Kernel 5.3 CVE
HIGH 7.5 CVE-2025-4410

SetupUtility: A buffer overflow vulnerability leads to arbitrary code execution._CVE-2025-4410

A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by execu...

Insyde Software InsydeH2O See in the Reference link CVE
HIGH 8.8 CVE-2025-8901

CVE-2025-8901_CVE-2025-8901

Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafte...

Google Chrome 139.0.7258.127 CVE
HIGH 8.8 CVE-2025-8882

CVE-2025-8882_CVE-2025-8882

Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to...

Google Chrome 139.0.7258.127 CVE
HIGH 8.8 CVE-2025-8880

CVE-2025-8880_CVE-2025-8880

Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (...

Google Chrome 139.0.7258.127 CVE
HIGH 8.8 CVE-2025-8879

CVE-2025-8879_CVE-2025-8879

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a cura...

Google Chrome 139.0.7258.127 CVE
HIGH 7.5 CVE-2025-8671

CVE-2025-8671_CVE-2025-8671

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 impleme...

SUSE Linux Enterprise Module for Development Tools 15 SP2 CVE
HIGH 7.5 CVE-2025-48989

Apache Tomcat: h2 DoS – Made You Reset_CVE-2025-48989

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apach...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
HIGH 8.8 CVE-2025-32451

CVE-2025-32451_CVE-2025-32451

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript ...

Foxit Foxit Reader 2025.1.0.27937 CVE