CVE-2025-1118Medium· 4.4▾ SunlitA flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensiti…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92035Critical· 9.6Sandbox escape due to incorrect boundary conditions in the Graphics component
CVE-2026-92048Critical· 9.0Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92064High· 8.8Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-92071Critical· 9.6Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVE-2026-54248Medium· 6.5Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks
CVE-2026-80946Medium· 5.5kernel: fuse: copy request headers via a stack buffer for io-uring (CVE-2026-80946)