VYPR

Vendor CVEs

Intel

All CVEs

2,357 total · sorted by risk
  • CVE-2017-5738CriNov 16, 2017
    risk 0.59cvss 9.1epss 0.02

    Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.

  • CVE-2017-5691CriJul 26, 2017
    risk 0.59cvss 9.0epss 0.01

    Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system…

  • CVE-2026-20702HigAug 11, 2026
    risk 0.58cvss epss 0.00

    Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may…

  • CVE-2013-4786HigJul 8, 2013
    risk 0.58cvss 7.5epss 0.79

    The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

  • CVE-2026-20887HigMay 12, 2026
    risk 0.57cvss epss 0.00

    Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable remote code execution. This…

  • CVE-2026-20753HigMay 12, 2026
    risk 0.57cvss epss 0.00

    Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when…

  • CVE-2025-35990HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack…

  • CVE-2025-20105HigMar 10, 2026
    risk 0.57cvss epss 0.00

    Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may…

  • CVE-2025-20064HigMar 10, 2026
    risk 0.57cvss epss 0.00

    Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may…

  • CVE-2025-33000HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of…

  • CVE-2025-24838HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable…

  • CVE-2025-24299HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable…

  • CVE-2025-24325HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-37355HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-53135HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's pt_mode module param behind CONFIG_BROKEN, i.e. disable support for virtualizing Intel PT via guest/host mode unless…

  • CVE-2024-36242HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.00

    Protection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23918HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-24986HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23981HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23497HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-21810HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-21807HigAug 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-46689HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-45217HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-42773HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-40070HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-38581HigMay 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-39425HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32204HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28737HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-23583HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.02

    Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

  • CVE-2023-28380HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-28410HigMay 10, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-27298HigMay 10, 2023
    risk 0.57cvss 8.8epss 0.01

    Uncontrolled search path in the WULT software maintained by Intel(R) before version 1.0.0 (commit id 592300b) may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-41784HigMay 10, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access

  • CVE-2022-36348HigFeb 16, 2023
    risk 0.57cvss 8.8epss 0.00

    Active debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-29277HigNov 15, 2022
    risk 0.57cvss 8.8epss 0.00

    Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL…

  • CVE-2022-33942HigNov 11, 2022
    risk 0.57cvss 8.8epss 0.01

    Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-26845HigNov 11, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-40250HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.00

    An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally…

  • CVE-2022-23182HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    Improper access control in the Intel(R) Data Center Manager software before version 4.1 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-21139HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-33115HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-0163HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.00

    Improper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-0162HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-0071HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2020-24489HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0101HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Buffer overflow in the BMC firmware for Intel(R) Server BoardM10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable an escalation of privilege via adjacent access.

  • CVE-2021-0070HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable an escalation of privilege via adjacent access.

  • CVE-2020-12339HigFeb 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

Page 2 of 48