VulnSea

intel has 12 CVEs on record between 2017 and 2026. 2 were published in the last 90 days. The busiest recent month was May 2026 with 3. The median CVSS is 7.2 (high). 8% have been exploited in the wild, in line with the corpus average. The most common weakness class is CWE-20 (4). Most affected products: tdx_module (5), celeron_1000m_firmware (1), connectivity_performance_suite (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
8% vs 1% corpus
Median CVSS
7.2
Publish → KEV
(1)
Last 90 days
2 prev 3

Products

  • tdx_module 5
  • celeron_1000m_firmware 1
  • connectivity_performance_suite 1
  • endpoint_management_assistant 1
  • ethernet_diagnostics_driver_iqvw32.sys 1
  • transfer_learning_tool 1
12
Total CVEs
0
Critical
1
CISA KEV
1
Exploited

intel vulnerabilities

CVEs affecting intel, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-39452High· 7.3
1mo ago

Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege

Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a…

Twilightintel · transfer_learning_toolEPSS 0.32%via NVD
CVE-2025-31936Medium· 5.7
1mo ago

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high comple…

Sunlitintel · xeon_6337p_firmwareEPSS 0.10%via NVD
CVE-2026-20887High· 7.5
4mo ago

Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service

Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack ma…

Twilightintel · visionEPSS 0.46%via NVD
CVE-2026-20772Medium· 6.7
4mo ago

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an au…

Sunlitintel · connectivity_performance_suiteEPSS 0.09%via NVD
CVE-2025-35990High· 8.8
4mo ago

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated us…

Twilightintel · endpoint_management_assistantEPSS 0.22%via NVD
CVE-2024-33607Medium· 5.6
1y ago

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

Sunlitintel · tdx_moduleEPSS 0.13%via NVD
CVE-2024-39283Medium· 6.0
2y ago

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

Sunlitintel · tdx_moduleEPSS 0.18%via NVD
CVE-2024-21801High· 7.1
2y ago

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.

Twilightintel · tdx_moduleEPSS 0.18%via NVD
CVE-2023-47855Medium· 6.0
2y ago

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

Sunlitintel · tdx_moduleEPSS 0.37%via NVD
CVE-2023-45745High· 7.9
2y ago

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

Twilightintel · tdx_moduleEPSS 0.38%via NVD
CVE-2022-21198High· 7.9
3y ago

Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Twilightintel · celeron_1000m_firmwareEPSS 0.15%via NVD
CVE-2015-2291High· 7.8CISA KEVPoC
9y ago

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …

Abyssalintel · ethernet_diagnostics_driver_iqvw32.sysEPSS 9.0%via NVD
intel vulnerabilities (CVEs) · VulnSea