CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

tianocore

edk2

33 known vulnerabilities · sorted by CVSS score

CVE-2025-2486
HIGH8.8

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.

tianocore / edk2+1
Local
Published Nov 26, 2025
Page 1 of 2
CVE-2023-45234
HIGH8.3

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

tianocore / edk2
Adjacent
Published Jan 16, 2024
CVE-2023-45230
HIGH8.3

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

tianocore / edk2
Adjacent
Published Jan 16, 2024
CVE-2023-45235
HIGH8.3

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

tianocore / edk2
Adjacent
Published Jan 16, 2024
CVE-2021-38575
HIGH8.1

NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.

tianocore / edk2+6
Network
Published Dec 1, 2021
CVE-2019-14586
HIGH8.0

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

tianocore / edk2+1
Adjacent
Published Nov 23, 2020
CVE-2019-14563
HIGH7.8

Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

tianocore / edk2+1
Local
Published Nov 23, 2020
CVE-2019-14575
HIGH7.8

Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.

tianocore / edk2+1
Local
Published Nov 23, 2020
CVE-2019-14584
HIGH7.8

Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

tianocore / edk2
Local
Published Jun 3, 2021
CVE-2021-28210
HIGH7.8

An unlimited recursion in DxeCore in EDK II.

tianocore / edk2
Local
Published Jun 11, 2021
CVE-2017-5731
HIGH7.8

Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.

tianocore / edk2
Local
Published Oct 28, 2019
CVE-2023-45232
HIGH7.5

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

tianocore / edk2
Network
Published Jan 16, 2024
CVE-2019-14559
HIGH7.5

Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.

tianocore / edk2
Network
Published Nov 23, 2020
CVE-2021-38576
HIGH7.5

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

tianocore / edk2+11
Network
Published Jan 3, 2022
CVE-2021-28213
HIGH7.5

Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.

tianocore / edk2
Network
Published Jun 11, 2021
CVE-2023-45233
HIGH7.5

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

tianocore / edk2
Network
Published Jan 16, 2024
CVE-2021-38578
HIGH7.4

Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

tianocore / edk2+6
Local
Published Mar 3, 2022
CVE-2022-36763
HIGH7.0

EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

tianocore / edk2
Local
Published Jan 9, 2024
CVE-2022-36764
HIGH7.0

EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

tianocore / edk2
Local
Published Jan 9, 2024
CVE-2022-36765
HIGH7.0

EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.

tianocore / edk2
Local
Published Jan 9, 2024