ZeroHour

Vulnerabilities

37 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20901
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege.

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

NVD description · AI analysis pending
4.0<1%
  • intel xeon bronze 3408u firmware
  • intel xeon gold 5403n firmware
  • intel xeon gold 5411n firmware
  • +1 more
CVE-2026-20789
Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2:

Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.

NVD description · AI analysis pending
8.4
group max
<1%
  • intel proset\/wireless wifi
CVE-2026-20913
Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3:

Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

NVD description · AI analysis pending
4.8<1%
  • intel neural compressor
CVE-2026-20898
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege.

Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

NVD description · AI analysis pending
8.5<1%
  • intel xeon 6315p firmware
  • intel xeon 6325p firmware
  • intel xeon 6333p firmware
  • +1 more
CVE-2026-20885
+2 in the same advisory: …20705 …20775
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0:

Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

NVD description · AI analysis pending
7.0
group max
<1%
  • intel tdx module
CVE-2026-20769
+2 in the same advisory: …20783 …20731
Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3:

Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

NVD description · AI analysis pending
6.9<1%
  • intel neural processing unit driver
CVE-2026-20765
+1 in the same advisory: …20763
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3:

Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

NVD description · AI analysis pending
4.6<1%
  • intel trust domain extensions guest
CVE-2026-20716
Improper access control for some Intel(R) Processors within Ring 3:

Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

NVD description · AI analysis pending
7.2<1%
  • intel xeon 634 firmware
  • intel xeon 636 firmware
  • intel xeon 638 firmware
  • +1 more
CVE-2026-13234
+3 in the same advisory: …13237 …13236 …13235
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scri

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

NVD description · AI analysis pending
6.1
group max
<1%
  • artificial intelligence project artificial intelligence