TianoCore.org

First CVE: Jun 11, 2021Active for: 5 years
27
CVEs Published
More CVEs Published than 46% of tracked CNAs
6.8
Avg CVEs / Year
More Avg CVEs / Year than 41% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by TianoCore.org as a CNA, 70.4% affect products that TianoCore.org develops as a vendor.

70.4%
29.6%
Self-reported: 19Third-party: 8

Of all the CVEs published that affect products developed by TianoCore.org, 43.2% are self-published by TianoCore.org as a CNA.

43.2%
56.8%
Self-published: 19Published by other CNAs: 25

Trends Over Time

The number and severity of CVEs published by TianoCore.org over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2021
5 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

Top CVEs

All CVEs published by TianoCore.org as a CNA, regardless of affected vendor or product.

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Mar 3, 20229.831NONO
EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control fl
Dec 9, 20258.427NONO
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
Dec 1, 20218.126NONO
EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be
Jan 16, 20248.825NONO
EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by
Jan 16, 20248.825NONO
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Aug 5, 20217.825NONO
EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitra
Aug 7, 20257.024NONO
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-pe
Jan 3, 20227.524NONO
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
Jun 11, 20217.524NONO
An unlimited recursion in DxeCore in EDK II.
Jun 11, 20217.824NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA27 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local9 (33.3%)
Network10 (37.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (29.6%)
Attack Complexity
Low23 (85.2%)
High4 (14.8%)
Unknown0 (0.0%)
User Interaction
None26 (96.3%)
Unknown0 (0.0%)
Required1 (3.7%)
Privileges Required
Low10 (37.0%)
High4 (14.8%)
None13 (48.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by TianoCore.org as a CNA.

Media Mentions

Media articles that mention a CVE ID published by TianoCore.org as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs