|
1491
|
- |
|
-
|
-
|
Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable l…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-20753
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1492
|
- |
|
-
|
-
|
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combin…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-20754
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1493
|
- |
|
-
|
-
|
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unpr…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-20772
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1494
|
- |
|
-
|
-
|
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversar…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-20794
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1495
|
- |
|
-
|
-
|
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary w…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-20879
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1496
|
- |
|
-
|
-
|
Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user co…
|
CWE-284
Improper Access Control
|
CVE-2026-20887
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1497
|
5.5 |
MEDIUM
Adjacent
|
-
|
-
|
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
|
CWE-93
CRLF Injection
|
CVE-2026-35504
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1498
|
8.2 |
HIGH
Adjacent
|
-
|
-
|
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions …
|
CWE-863
Incorrect Authorization
|
CVE-2026-26289
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1499
|
5.7 |
MEDIUM
Adjacent
|
-
|
-
|
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.
|
CWE-863
Incorrect Authorization
|
CVE-2026-33570
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1500
|
6.3 |
MEDIUM
Adjacent
|
-
|
-
|
PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
|
CWE-863
Incorrect Authorization
|
CVE-2026-35555
|
2026-05-14 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|