Insyde Software

First CVE: Jun 11, 2025Active for: 1 year
15
CVEs Published
More CVEs Published than 35% of tracked CNAs
7.5
Avg CVEs / Year
More Avg CVEs / Year than 45% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 75% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Insyde Software as a CNA, 0.0% affect products that Insyde Software develops as a vendor.

100.0%
Self-reported: 0Third-party: 15

Of all the CVEs published that affect products developed by Insyde Software, 0.0% are self-published by Insyde Software as a CNA.

100.0%
Self-published: 0Published by other CNAs: 104

Trends Over Time

The number and severity of CVEs published by Insyde Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2025
13 months ago
Most Recent CVE
Jan 14, 2026
191 days ago

Top CVEs

All CVEs published by Insyde Software as a CNA, regardless of affected vendor or product.

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Jan 14, 20267.829NONO
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Jan 14, 20267.829NONO
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information abo
Jul 30, 20258.229NONO
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information abo
Jul 30, 20258.228NONO
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for more information abo
Jul 30, 20258.228NONO
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Jan 14, 20267.826NONO
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
Jan 14, 20267.826NONO
Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
Dec 12, 20258.226NONO
A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.
Aug 13, 20257.526NONO
UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.
Aug 13, 20257.525NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA15 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local15 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (73.3%)
High4 (26.7%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (33.3%)
High10 (66.7%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Insyde Software as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Insyde Software as a CNA — matched by CVE ID, not by organization name.

Top CWEs