Products › Endpoints, servers and mobile
Endpoints, servers and mobile
Hardware, firmware and drivers
BIOS and firmware, baseboard management controllers (BMC) and drivers or tools shipped by hardware makers.
For example: Intel, AMI, GIGABYTE, Dell.
-
1 vulnerability added in the last 12 months
-
10 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- AMI 1 vulnerability
- Arm 1 vulnerability
- ASUS 1 vulnerability · 1 in the last 12 months
- Dell 1 vulnerability
- GIGABYTE 4 vulnerabilities
- Intel 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Operating systems 286 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1ASUS Live Update
CVE-2025-59374ASUS Live Update Embedded Malicious Code Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 17, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 2AMI MegaRAC SPx
CVE-2024-54085AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 25, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 3GIGABYTE App Center / AORUS (pilote GDrv)
CVE-2018-19323RansomwareCVE from 2018, added in 2022
GIGABYTE Multiple Products Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 4Intel Active Management Technology (AMT)
CVE-2017-5689CVE from 2017, added in 2022
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 28, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 5Intel Ethernet Diagnostics Driver for Windows
CVE-2015-2291RansomwareCVE from 2015, added in 2023
Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 6GIGABYTE App Center / AORUS (pilote GDrv)
CVE-2018-19320RansomwareCVE from 2018, added in 2022
GIGABYTE Multiple Products Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 7GIGABYTE App Center / AORUS (pilote GDrv)
CVE-2018-19321RansomwareCVE from 2018, added in 2022
GIGABYTE Multiple Products Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 8GIGABYTE App Center / AORUS (pilote GDrv)
CVE-2018-19322RansomwareCVE from 2018, added in 2022
GIGABYTE Multiple Products Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 9Dell dbutil Driver
CVE-2021-21551Dell dbutil Driver Insufficient Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 31, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 10Arm Trusted Firmware
CVE-2021-27562Arm Trusted Firmware Out-of-Bounds Write Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 5.5 (medium)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.