Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · st

st

· 1 Critical

Total CVEs

29

Critical

1

Products

306

Search All CVEs →

29

Products (306)

x-cube-azrtos-wl7 CVEsx-cube-azrt-h7rs7 CVEsx-cube-azrtos-f47 CVEsx-cube-azrtos-f77 CVEsx-cube-azrtos-g07 CVEsx-cube-azrtos-g47 CVEsx-cube-azrtos-h77 CVEsx-cube-azrtos-l47 CVEsx-cube-azrtos-l57 CVEsx-cube-azrtos-wb7 CVEsstm32cube middleware6 CVEsstm32h7b36 CVEsstm32l42 CVEsstm32l412c82 CVEsstm32l412cb2 CVEsstm32l412k82 CVEsstm32l412kb2 CVEsstm32l412r82 CVEsstm32l412rb2 CVEsstm32l412t82 CVEsstm32l412tb2 CVEsstm32l422cb2 CVEsstm32l422kb2 CVEsstm32l422rb2 CVEsstm32l422tb2 CVEsstm32l431cb2 CVEsstm32l431cc2 CVEsstm32l431kb2 CVEsstm32l431kc2 CVEsstm32l431rb2 CVEsstm32l431rc2 CVEsstm32l431vc2 CVEsstm32l432kb2 CVEsstm32l432kc2 CVEsstm32l433cb2 CVEsstm32l433cc2 CVEsstm32l433rb2 CVEsstm32l433rc2 CVEsstm32l433vc2 CVEsstm32l442kc2 CVEsstm32l443cc2 CVEsstm32l443rc2 CVEsstm32l443vc2 CVEsstm32l451cc2 CVEsstm32l451ce2 CVEsstm32l451rc2 CVEsstm32l451re2 CVEsstm32l451vc2 CVEsstm32l451ve2 CVEsstm32l452cc2 CVEsstm32l452ce2 CVEsstm32l452rc2 CVEsstm32l452re2 CVEsstm32l452vc2 CVEsstm32l452ve2 CVEsstm32l462ce2 CVEsstm32l462re2 CVEsstm32l462ve2 CVEsstm32l471qe2 CVEsstm32l471qg2 CVEsstm32l471re2 CVEsstm32l471rg2 CVEsstm32l471ve2 CVEsstm32l471vg2 CVEsstm32l471ze2 CVEsstm32l471zg2 CVEsstm32l475rc2 CVEsstm32l475re2 CVEsstm32l475rg2 CVEsstm32l475vc2 CVEsstm32l475ve2 CVEsstm32l475vg2 CVEsstm32l476je2 CVEsstm32l476jg2 CVEsstm32l476me2 CVEsstm32l476mg2 CVEsstm32l476qe2 CVEsstm32l476qg2 CVEsstm32l476rc2 CVEsstm32l476re2 CVEsstm32l476rg2 CVEsstm32l476vc2 CVEsstm32l476ve2 CVEsstm32l476vg2 CVEsstm32l476ze2 CVEsstm32l476zg2 CVEsstm32l486jg2 CVEsstm32l486qg2 CVEsstm32l486rg2 CVEsstm32l486vg2 CVEsstm32l486zg2 CVEsstm32l496ae2 CVEsstm32l496ag2 CVEsstm32l496qe2 CVEsstm32l496qg2 CVEsstm32l496re2 CVEsstm32l496rg2 CVEsstm32l496ve2 CVEsstm32l496vg2 CVEsstm32l496wg2 CVEsstm32l496ze2 CVEsstm32l496zg2 CVEsstm32l4 firmware2 CVEsstm32l4a6ag2 CVEsstm32l4a6qg2 CVEsstm32l4a6rg2 CVEsj-safe32 CVEsstm32l4a6zg2 CVEsstsafe-j2 CVEsstsafe-j firmware2 CVEsstm32cubel4 firmware2 CVEsstm32l4a6vg2 CVEsj-safe3 firmware2 CVEsstm32f42 CVEsstm32f4 firmware2 CVEsstm32f72 CVEsstm32f7 firmware2 CVEsstm32h72 CVEsstm32h7 firmware2 CVEsstm32l02 CVEsstm32l0 firmware2 CVEsstm32l12 CVEsstm32l1 firmware2 CVEsstm32f070c61 CVEsstm32f070c6 firmware1 CVEsstm32f070cb1 CVEsstm32f070cb firmware1 CVEsstm32f070f61 CVEsstm32f070f6 firmware1 CVEsstm32f070rb1 CVEsstm32f070rb firmware1 CVEsstm32f071c81 CVEsstm32f071c8 firmware1 CVEsstm32f071cb1 CVEsstm32f071cb firmware1 CVEsstm32f071rb1 CVEsstm32f071rb firmware1 CVEsstm32f071v81 CVEsstm32f071v8 firmware1 CVEsstm32f071vb1 CVEsstm32f071vb firmware1 CVEsstm32f072c81 CVEsstm32f072c8 firmware1 CVEsstm32f072cb1 CVEsstm32f072cb firmware1 CVEsstm32f072r81 CVEsstm32f072r8 firmware1 CVEsstm32f072rb1 CVEsstm32f072rb firmware1 CVEsbluenrg-21 CVEsstm32f072v8 firmware1 CVEsstm32f072vb1 CVEsstm32f072vb firmware1 CVEsstm32f078cb1 CVEsstm32f078cb firmware1 CVEsstm32f078rb1 CVEsstm32f078rb firmware1 CVEsstm32f078vb1 CVEsstm32f078vb firmware1 CVEsstm32f091cb1 CVEsstm32f091cb firmware1 CVEsstm32f091cc1 CVEsstm32f091cc firmware1 CVEsstm32f091rb1 CVEsstm32f091rb firmware1 CVEsstm32f091rc1 CVEsstm32f091rc firmware1 CVEsstm32f091vb1 CVEsstm32f091vb firmware1 CVEsstm32f091vc1 CVEsstm32f091vc firmware1 CVEsstm32f098cc1 CVEsstm32f098cc firmware1 CVEsstm32f098rc1 CVEsstm32f098rc firmware1 CVEsstm32f098vc1 CVEsstm32f098vc firmware1 CVEsstm32f11 CVEsstm32f1031 CVEsstm32f103 firmware1 CVEsstm32f1 firmware1 CVEswb551 CVEsx-cube-safea11 CVEsstm32f072v81 CVEsftp service1 CVEsst33tphf20i2c1 CVEsst33tphf20i2c firmware1 CVEsst33tphf20spi1 CVEsst33tphf20spi firmware1 CVEsst33tphf2ei2c1 CVEsst33tphf2ei2c firmware1 CVEsst33tphf2espi1 CVEsst33tphf2espi firmware1 CVEsst54-android-packages-apps-nfc1 CVEsstm32 mw usb host1 CVEsstm32cubef01 CVEsstm32cubef11 CVEsstm32cubef21 CVEsstm32cubef31 CVEsstm32cubef41 CVEsstm32cubef71 CVEsstm32cubeg01 CVEsstm32cubeg41 CVEsstm32cubeh71 CVEsstm32cubeide1 CVEsstm32cubel01 CVEsstm32cubel11 CVEsstm32cubel41 CVEsstm32cubel4\+1 CVEsstm32cubel51 CVEsstm32cubemonitor1 CVEsstm32cubemp11 CVEsstm32cubemx1 CVEsstm32cubeprogrammer1 CVEsstm32cubewb1 CVEsstm32cubewl1 CVEsstm32f030c61 CVEsstm32f030c6 firmware1 CVEsstm32f030c81 CVEsstm32f030c8 firmware1 CVEsstm32f030cc1 CVEsstm32f030cc firmware1 CVEsstm32f030f41 CVEsstm32f030f4 firmware1 CVEsstm32f030k61 CVEsstm32f030k6 firmware1 CVEsstm32f030r81 CVEsstm32f030r8 firmware1 CVEsstm32f030rc1 CVEsstm32f030rc firmware1 CVEsstm32f031c41 CVEsstm32f031c4 firmware1 CVEsstm32f031c61 CVEsstm32f031c6 firmware1 CVEsstm32f031e61 CVEsstm32f031e6 firmware1 CVEsstm32f031f41 CVEsstm32f031f4 firmware1 CVEsstm32f031f61 CVEsstm32f031f6 firmware1 CVEsstm32f031g41 CVEsstm32f031g4 firmware1 CVEsstm32f031g61 CVEsstm32f031g6 firmware1 CVEsstm32f031k41 CVEsstm32f031k4 firmware1 CVEsstm32f038c61 CVEsstm32f038c6 firmware1 CVEsstm32f038e61 CVEsstm32f038e6 firmware1 CVEsstm32f038f61 CVEsstm32f038f6 firmware1 CVEsstm32f038g61 CVEsstm32f038g6 firmware1 CVEsstm32f038k61 CVEsstm32f038k6 firmware1 CVEsstm32f042c41 CVEsstm32f042c4 firmware1 CVEsstm32f042c61 CVEsstm32f042c6 firmware1 CVEsstm32f042f41 CVEsstm32f042f4 firmware1 CVEsstm32f042f61 CVEsstm32f042f6 firmware1 CVEsstm32f042g41 CVEsstm32f042g4 firmware1 CVEsstm32f042g61 CVEsstm32f042g6 firmware1 CVEsstm32f042k41 CVEsstm32f042k4 firmware1 CVEsstm32f042k61 CVEsstm32f042k6 firmware1 CVEsstm32f042t61 CVEsstm32f042t6 firmware1 CVEsstm32f048c61 CVEsstm32f048c6 firmware1 CVEsstm32f048g61 CVEsstm32f048g6 firmware1 CVEsstm32f048t61 CVEsstm32f048t6 firmware1 CVEsstm32f051c41 CVEsstm32f051c4 firmware1 CVEsstm32f051c61 CVEsstm32f051c6 firmware1 CVEsstm32f051c81 CVEsstm32f051c8 firmware1 CVEsstm32f051k41 CVEsstm32f051k4 firmware1 CVEsstm32f051k61 CVEsstm32f051k6 firmware1 CVEsstm32f051k81 CVEsstm32f051k8 firmware1 CVEsstm32f051r41 CVEsstm32f051r4 firmware1 CVEsstm32f051r61 CVEsstm32f051r6 firmware1 CVEsstm32f051r81 CVEsstm32f051r8 firmware1 CVEsstm32f051t81 CVEsstm32f051t8 firmware1 CVEsstm32f058c81 CVEsstm32f058c8 firmware1 CVEsstm32f058r81 CVEsstm32f058r8 firmware1 CVEsstm32f058t81 CVEsstm32f058t8 firmware1 CVEs

Recent Vulnerabilities

View all 29
CVE-2024-50597MEDIUM 4.3

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c

CVE-2024-50596MEDIUM 4.3

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

CVE-2024-50595MEDIUM 4.3

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c

CVE-2024-50594MEDIUM 4.3

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

CVE-2024-50385MEDIUM 6.5

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c

CVE-2024-50384MEDIUM 6.5

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

CVE-2024-45064HIGH 8.5

A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-36629MEDIUM 5.5

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

CVE-2023-50096HIGH 7.5

STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.

CVE-2021-42553MEDIUM 6.8

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.

CVE-2021-43393MEDIUM 6.2

STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.

CVE-2021-43392MEDIUM 6.2

STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.

CVE-2021-34268MEDIUM 4.6

An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) via a malformed USB device packet.

CVE-2021-34267MEDIUM 4.6

An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) when the system tries to communicate with the connected endpoint.

CVE-2021-34262MEDIUM 6.8

A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.

CVE-2021-34261MEDIUM 4.6

An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature.

CVE-2021-34260MEDIUM 6.8

A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.

CVE-2021-34259MEDIUM 6.8

A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.

CVE-2021-29414MEDIUM 6.1

STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

CVE-2020-27212HIGH 7.0

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.

CVE-2020-20949MEDIUM 5.9

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

CVE-2020-13466MEDIUM 6.8

STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.

CVE-2020-8004HIGH 7.5

STMicroelectronics STM32F1 devices have Incorrect Access Control.

CVE-2019-19192MEDIUM 6.5

The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attribute Protocol (ATT) requests on reception, allowing attackers in radio range to cause an event deadlock or crash via crafted packets.

CVE-2019-16863MEDIUM 5.9

STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.