CVEリスト - 高リスク・悪用確認済み脆弱性

NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。

Assigner(CNA/発行元):[email protected] この条件を外す

CVSS スコア
表示中 120 / 51
«« 先頭 « 前へ 1 / 3 次へ »
CVE 説明 CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-22834 AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the resource in an unexpected state and potentially impact confidentiality, integrity, and availability. 4.2 0.07% 2025-08-12 2025-10-02
CVE-2024-33658 APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. Successful exploitation of this vulnerability may lead to privilege escalation and potentially arbitrary code execution, and impact Integrity. 4.4 0.17% 2024-11-12 2025-10-02
CVE-2025-22833 APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of this vulnerability may lead to arbitrary code execution. 4.6 0.03% 2025-10-14 2025-10-22
CVE-2023-34469 AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical network. A successful exploit of this vulnerability may lead to a loss of confidentiality.  4.9 0.07% 2023-09-12 2024-11-21
CVE-2024-33660 An exploit is possible where an actor with physical access can manipulate SPI flash without being detected. 5.2 0.11% 2024-11-12 2025-10-02
CVE-2023-34344 AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure. 5.3 0.38% 2023-06-12 2024-11-21
CVE-2024-33659 AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability. 5.7 0.07% 2025-02-11 2025-10-02
CVE-2023-34472 AMI SPx contains a vulnerability in the BMC where an Attacker may cause an improper neutralization of CRLF sequences in HTTP Headers. A successful exploit of this vulnerability may lead to a loss of integrity. 5.7 0.25% 2023-07-05 2024-11-21
CVE-2025-33043 APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of integrity. 5.8 0.05% 2025-05-29 2025-11-03
CVE-2025-33044 APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitation of this vulnerability may lead to memory corruption and impact Integrity and Availability. 5.9 0.07% 2025-10-14 2026-04-29
CVE-2025-22832 APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability. 5.9 0.05% 2025-10-14 2026-04-29
CVE-2025-22831 APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability. 5.9 0.05% 2025-10-14 2026-04-29
CVE-2023-34342 AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure, or data tampering. 6.0 0.19% 2023-06-12 2024-11-21
CVE-2023-34471 AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentiality, integrity, and authentication. 6.3 0.05% 2023-07-05 2024-11-21
CVE-2023-34345 AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lead to information disclosure. 6.5 0.26% 2023-06-12 2024-11-21
CVE-2023-34473 AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. 6.6 0.15% 2023-07-05 2024-11-21
CVE-2024-2315 APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability. 6.8 0.08% 2024-11-12 2025-10-02
CVE-2023-34470 AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability. 6.8 0.06% 2023-09-12 2024-11-21
CVE-2023-34338 AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.  7.1 0.17% 2023-07-05 2024-11-21
CVE-2025-58770 APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulnerability can lead to escalation of authorization and potentially impact Integrity and Availability. 7.2 0.01% 2025-12-12 2026-01-12
«« 先頭 « 前へ 1 / 3 次へ »
cvelogic Threat Intelligence