Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25

Vendors · microchip

microchip

· 8 Critical

Total CVEs

49

Critical

8

Products

209

Search All CVEs →

49

Products (209)

timeprovider 4100 firmware11 CVEstimeprovider 410011 CVEsrn4870 firmware8 CVEsrn48708 CVEssyncserver s1007 CVEssyncserver s2007 CVEssyncserver s300 firmware7 CVEssyncserver s350 firmware7 CVEssyncserver s3507 CVEssyncserver s3007 CVEssyncserver s2507 CVEssyncserver s200 firmware7 CVEssyncserver s250 firmware7 CVEssyncserver s100 firmware7 CVEspic lightblue explorer demo5 CVEsbm705 CVEsbm70 firmware5 CVEsbm715 CVEsbm71 firmware5 CVEsbm785 CVEsbm78 firmware5 CVEsbm835 CVEsbm83 firmware5 CVEsrn4871 firmware5 CVEsrn48715 CVEspic lightblue explorer demo firmware5 CVEsis18714 CVEsis1871 firmware4 CVEsis1870 firmware4 CVEsis18704 CVEsatsama5d26c-cn firmware3 CVEsatsama5d26c-cnr3 CVEsatsama5d26c-cnr firmware3 CVEsatsama5d26c-cu3 CVEsatsama5d26c-cu firmware3 CVEsatsama5d26c-cur3 CVEsatsama5d26c-cur firmware3 CVEsatsama5d27-som13 CVEsatsama5d27-som1 firmware3 CVEsatsama5d27-wlsom13 CVEsatsama5d27-wlsom1 firmware3 CVEsatsama5d27c-cn3 CVEsatsama5d27c-cn firmware3 CVEsatsama5d27c-cnr3 CVEsatsama5d27c-cnr firmware3 CVEsatsama5d27c-cnrvao3 CVEsatsama5d27c-cnrvao firmware3 CVEsatsama5d27c-cnvao3 CVEsatsama5d27c-cnvao firmware3 CVEsatsama5d27c-cu firmware3 CVEsatsama5d27c-cur3 CVEsatsama5d27c-cur firmware3 CVEsatsama5d27c-d1g-cu3 CVEsatsama5d27c-d1g-cu firmware3 CVEsatsama5d27c-d1g-cur3 CVEsatsama5d27c-d1g-cur firmware3 CVEsatsama5d27c-d5m-cu3 CVEsatsama5d27c-d5m-cu firmware3 CVEsatsama5d27c-d5m-cur3 CVEsatsama5d27c-d5m-cur firmware3 CVEsatsama5d27c-ld1g-cu3 CVEsatsama5d27c-ld1g-cu firmware3 CVEsatsama5d27c-ld1g-cur3 CVEsatsama5d27c-ld1g-cur firmware3 CVEsatsama5d27c-ld2g-cu3 CVEsatsama5d27c-ld2g-cu firmware3 CVEsatsama5d27c-ld2g-cur3 CVEsatsama5d27c-ld2g-cur firmware3 CVEsatsama5d28c-cn3 CVEsatsama5d28c-cn firmware3 CVEsatsama5d28c-cnr3 CVEsatsama5d28c-cnr firmware3 CVEsatsama5d28c-cu3 CVEsatsama5d28c-cu firmware3 CVEsatsama5d28c-cur3 CVEsatsama5d28c-cur firmware3 CVEsatsama5d28c-d1g-cu3 CVEsatsama5d28c-d1g-cu firmware3 CVEsatsama5d28c-d1g-cur3 CVEsatsama5d28c-d1g-cur firmware3 CVEsatsama5d28c-ld1g-cu3 CVEsatsama5d28c-ld1g-cu firmware3 CVEsatsama5d28c-ld1g-cur3 CVEsatsama5d28c-ld1g-cur firmware3 CVEsatsama5d28c-ld2g-cu3 CVEsatsama5d28c-ld2g-cu firmware3 CVEsatsama5d28c-ld2g-cur3 CVEsatsama5d28c-ld2g-cur firmware3 CVEsatsama5d31a-cfu3 CVEsatsama5d31a-cfu firmware3 CVEsatsama5d31a-cfur3 CVEsatsama5d31a-cfur firmware3 CVEsatsama5d31a-cu3 CVEsatsama5d31a-cu firmware3 CVEsatsama5d31a-cur3 CVEsatsama5d31a-cur firmware3 CVEsatsama5d33a-cu3 CVEsatsama5d33a-cu firmware3 CVEsatsama5d33a-cur3 CVEsatsama5d33a-cur firmware3 CVEsatsama5d34a-cu3 CVEsatsama5d34a-cu firmware3 CVEsatsama5d34a-cur3 CVEsatsama5d34a-cur firmware3 CVEsatsama5d35a-cn3 CVEsatsama5d35a-cn firmware3 CVEsatsama5d35a-cnr3 CVEsatsama5d35a-cnr firmware3 CVEsatsama5d35a-cu3 CVEsatsama5d35a-cu firmware3 CVEsatsama5d35a-cur3 CVEsatsama5d35a-cur firmware3 CVEsatsama5d36a-cn3 CVEsatsama5d36a-cn firmware3 CVEsatsama5d36a-cnr3 CVEsatsama5d36a-cnr firmware3 CVEsatsama5d36a-cu3 CVEsatsama5d36a-cu firmware3 CVEsatsama5d36a-cur3 CVEsatsama5d36a-cur firmware3 CVEsatsama5d41a-cu3 CVEsatsama5d41a-cu firmware3 CVEsatsama5d41a-cur3 CVEsatsama5d41a-cur firmware3 CVEsatsama5d41b-cu3 CVEsatsama5d41b-cu firmware3 CVEsatsama5d41b-cur3 CVEsatsama5d41b-cur firmware3 CVEsatsama5d42a-cu3 CVEsatsama5d42a-cu firmware3 CVEsatsama5d42a-cur3 CVEsatsama5d42a-cur firmware3 CVEsatsama5d42b-cu3 CVEsatsama5d42b-cu firmware3 CVEsatsama5d42b-cur3 CVEsatsama5d42b-cur firmware3 CVEsatsama5d43a-cu3 CVEsatsama5d43a-cu firmware3 CVEsatsama5d43a-cur3 CVEsatsama5d43a-cur firmware3 CVEsatsama5d43b-cu3 CVEsatsama5d43b-cu firmware3 CVEsatsama5d43b-cur3 CVEsatsama5d43b-cur firmware3 CVEsatsama5d44a-cu3 CVEsatsama5d44a-cu firmware3 CVEsatsama5d44a-cur3 CVEsatsama5d44a-cur firmware3 CVEsatsama5d44b-cu3 CVEsatsama5d44b-cu firmware3 CVEsatsama5d44b-cur3 CVEsatsama5d44b-cur firmware3 CVEsmaxview storage manager3 CVEsatsama5d27c-cu3 CVEsatsama5d21c-cu3 CVEsatsama5d21c-cu firmware3 CVEsatsama5d21c-cur3 CVEsatsama5d21c-cur firmware3 CVEsatsama5d225c-d1m-cur3 CVEsatsama5d225c-d1m-cur firmware3 CVEsatsama5d22c-cn3 CVEsatsama5d22c-cn firmware3 CVEsatsama5d22c-cnr3 CVEsatsama5d22c-cnr firmware3 CVEsatsama5d22c-cu3 CVEsatsama5d22c-cu firmware3 CVEsatsama5d22c-cur3 CVEsatsama5d22c-cur firmware3 CVEsatsama5d23c-cn3 CVEsatsama5d23c-cn firmware3 CVEsatsama5d23c-cnr3 CVEsatsama5d23c-cnr firmware3 CVEsatsama5d23c-cu3 CVEsatsama5d23c-cu firmware3 CVEsatsama5d23c-cur3 CVEsatsama5d23c-cur firmware3 CVEsatsama5d24c-cu3 CVEsatsama5d24c-cu firmware3 CVEsatsama5d24c-cuf3 CVEsatsama5d24c-cuf firmware3 CVEsatsama5d24c-cur3 CVEsatsama5d24c-cur firmware3 CVEsatsama5d26c-cn3 CVEswbz451 firmware2 CVEspic32cx1012bz250482 CVEsrn46782 CVEsrn4678 firmware2 CVEsmplab ide2 CVEsmiwi2 CVEscryptoauthlib2 CVEsbm77 firmware2 CVEsbm772 CVEsbm64 firmware2 CVEsbm642 CVEstimepictra2 CVEswbz4512 CVEspic32cx1012bz25048 firmware2 CVEsmplab network creator1 CVEsadvanced software framework 41 CVEsatmel toolbox1 CVEsatsamb111 CVEsmplab harmony1 CVEsadvanced software framework1 CVEsmicrochip libraries for applications1 CVEsdt100112 firmware1 CVEsdt1001121 CVEsatmsamb11 blusdk smart1 CVEssyncserver s6501 CVEssyncserver s650 firmware1 CVEs

Recent Vulnerabilities

View all 49
CVE-2026-3010MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.

CVE-2026-2844HIGH 7.5

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.

CVE-2025-47904MEDIUM 4.1

Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.

CVE-2025-47902HIGH 8.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This issue affects Time Provider 4100: before 2.5.

CVE-2025-47901HIGH 8.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.

CVE-2025-47900HIGH 8.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Injection.This issue affects Time Provider 4100: before 2.5.

CVE-2024-9054HIGH 8.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-7801MEDIUM 6.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-43687MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-43686MEDIUM 6.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-43685CRITICAL 9.8

Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-43684HIGH 8.8

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.

CVE-2024-43683MEDIUM 6.1

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.

CVE-2024-7490CRITICAL 9.8

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option. This issue affects Advanced Software Framework: through 3.52.0.2574. ASF is no longer being supported. Apply provided workaround or migrate to an actively maintained framework.

CVE-2023-51438CRITICAL 10.0

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.

CVE-2024-22216CRITICAL 10.0

In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).

CVE-2020-27636CRITICAL 9.1

In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.

CVE-2023-23588MEDIUM 6.2

A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application. A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.

CVE-2022-40022CRITICAL 9.8

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

CVE-2022-45192MEDIUM 6.5

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request.

CVE-2022-45191MEDIUM 6.5

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values.

CVE-2022-45190MEDIUM 5.3

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.

CVE-2022-40480MEDIUM 6.5

Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.

CVE-2022-46403HIGH 8.6

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.

CVE-2022-46402MEDIUM 6.5

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.