Insyde Software
First CVE: Jun 11, 2025Active for: 1 year
15
CVEs Published
More CVEs Published than 35% of tracked CNAs
7.5
Avg CVEs / Year
More Avg CVEs / Year than 45% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 75% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Insyde Software as a CNA, 0.0% affect products that Insyde Software develops as a vendor.
100.0%
Self-reported: 0Third-party: 15
Of all the CVEs published that affect products developed by Insyde Software, 0.0% are self-published by Insyde Software as a CNA.
100.0%
Self-published: 0Published by other CNAs: 104
Trends Over Time
The number and severity of CVEs published by Insyde Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2025
13 months ago
Most Recent CVE
Jan 14, 2026
191 days ago
Top CVEs
All CVEs published by Insyde Software as a CNA, regardless of affected vendor or product.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12053HIGH The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow. | Jan 14, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-12050HIGH The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow. | Jan 14, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-4421HIGH The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information abo | Jul 30, 2025 | 8.2 | 29 | NO | NO |
CVE-2025-4423HIGH The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information abo | Jul 30, 2025 | 8.2 | 28 | NO | NO |
CVE-2025-4422HIGH The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information abo | Jul 30, 2025 | 8.2 | 28 | NO | NO |
CVE-2025-12052HIGH The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow. | Jan 14, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-12051HIGH The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow. | Jan 14, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-10451HIGH Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption. | Dec 12, 2025 | 8.2 | 26 | NO | NO |
CVE-2025-4410HIGH A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code. | Aug 13, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-4276HIGH UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level. | Aug 13, 2025 | 7.5 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA15 CVEs
13%
87%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local15 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (73.3%)
High4 (26.7%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (33.3%)
High10 (66.7%)
None0 (0.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Insyde Software as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Insyde Software as a CNA — matched by CVE ID, not by organization name.