21 Total CVEs
21 AI Analyzed
0 CISA KEV
1 Critical

Profile

0% ended up actively exploited 0 of 21 added to CISA KEV
5% rated critical (CVSS 9.0+) 1 critical, 20 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

21 CVEs in the last 12 months

Products

  • zephyr8
  • Zephyr RTOS7
  • Zephyr6

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-21 of 21 CVEs
CVE-2026-9771
Analyzed
8.8
zephyrproject zephyr

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util

2026-08-18
CVE-2026-8718
Analyzed
8.4
zephyrproject Zephyr RTOS

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls

2026-08-11
CVE-2026-8023
Analyzed
7.5
zephyrproject Zephyr RTOS

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM...

2026-06-30
CVE-2026-7656
Analyzed
8.1
zephyrproject Zephyr RTOS

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr

2026-06-30
CVE-2026-13214
Analyzed
9.8
zephyrproject zephyr

A stack-based buffer overflow in the OCPP 1.6 client of the Zephyr RTOS allows remote attackers to cause a denial of service or potentially execute ar...

2026-08-25
CVE-2026-13212
Analyzed
8.8
zephyrproject zephyr

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring

2026-08-25
CVE-2026-12522
Analyzed
8.8
zephyrproject Zephyr

The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800

2026-08-20
CVE-2026-12366
Analyzed
8.8
zephyrproject Zephyr

Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace

2026-08-15
CVE-2026-12364
Analyzed
8.4
zephyrproject zephyr

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg

2026-08-16
CVE-2026-11810
Analyzed
7.5
zephyrproject Zephyr

The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub

2026-08-11
CVE-2026-10849
Analyzed
8.2
zephyrproject Zephyr

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in resp...

2026-08-04
CVE-2026-10848
Analyzed
7
zephyrproject Zephyr RTOS

The OCPP 1

2026-08-03
CVE-2026-10685
Analyzed
7.6
zephyrproject zephyr

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt

2026-08-01
CVE-2026-10673
Analyzed
8.3
zephyrproject zephyr

The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111

2026-07-17
CVE-2026-10667
Analyzed
7.8
zephyrproject zephyr

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace

2026-07-13
CVE-2026-10666
Analyzed
8.1
zephyrproject Zephyr

parse_ipv4() in subsys/net/ip/utils

2026-07-13
CVE-2026-10665
Analyzed
7.4
zephyrproject zephyr

In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto

2026-07-13
CVE-2026-10658
Analyzed
7.1
zephyrproject Zephyr RTOS

A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data

2026-06-23
CVE-2026-10651
Analyzed
7.1
zephyrproject Zephyr RTOS

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser

2026-06-23
CVE-2026-10646
Analyzed
7.4
zephyrproject Zephyr

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo

2026-06-28
CVE-2026-10643
Analyzed
8.7
zephyrproject Zephyr RTOS

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet

2026-06-28