TianoCore
CVE Numbering Authority
Latest CVE published
Overview
TianoCore is a CVE Numbering Authority that has published 27 CVE records since 2021. It is currently classified as active, with 8 CVEs published in the last two years. Its CVE data quality is graded A (91.7% overall completeness).
Among the 370 CNAs tracked here, TianoCore ranks #223 by CVE volume and reports more complete records than 37% of all CNAs.
Data quality report card
How complete and consistent TianoCore's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often TianoCore also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
91.7%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of TianoCore's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of TianoCore's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories TianoCore most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-122Heap-based Buffer Overflow4 CVEs
- CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer3 CVEs
- CWE-125Out-of-bounds Read3 CVEs
- CWE-200Exposure of Sensitive Information to an Unauthorized Actor2 CVEs
- CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')2 CVEs
- CWE-124Buffer Underwrite ('Buffer Underflow')2 CVEs
- CWE-190Integer Overflow or Wraparound2 CVEs
- CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1 CVE
Publishing activity by year
How many CVEs TianoCore has published each year.
Top vendors
The vendors TianoCore publishes the most CVEs for.
Top products
The products TianoCore publishes the most CVEs for.
- EDK226 CVEs
- Azure Linux 3.0 x6411 CVEs
- CBL Mariner 2.0 ARM11 CVEs
- Azure Linux 3.0 ARM11 CVEs
- CBL Mariner 2.0 x6411 CVEs
- EDK II6 CVEs
- cbl2 edk2 20230301gitf80f052277c8-42 on CBL Mariner 2.05 CVEs
- cbl2 qemu 6.2.0-26 on CBL Mariner 2.04 CVEs
Latest CVEs
The most recent CVEs assigned by TianoCore.
- CVE-2025-2296CWE-20
Un-verified kernel bypass Secure Boot mechanism in direct boot mode
High · CVSS 8.4EPSS 0.8%2025-12-09 - CVE-2024-38798CWE-200
Uncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilege
Medium · CVSS 5.8EPSS 0.1%2025-12-09 - CVE-2024-38805CWE-190
iSCSI Remote Memory Corruption and Denial of Service
Medium · CVSS 6.3EPSS 0.2%2025-08-12 - CVE-2025-3770CWE-693
SMM IDT Privilege Escalation Vulnerability
High · CVSS 7.0EPSS 0.2%2025-08-07 - CVE-2024-38797CWE-125Medium · CVSS 4.6EPSS 0.2%2025-04-07
- CVE-2025-2295CWE-190
Potential iSCSI R2T PDU Vulnerability
Low · CVSS 3.5EPSS 0.2%2025-03-14 - CVE-2024-38796CWE-122
Integer overflow in PeCoffLoaderRelocateImage
Medium · CVSS 5.9EPSS 0.4%2024-09-27 - CVE-2024-1298CWE-369
Integer Overflow caused by divide by zero during S3 suspension
Medium · CVSS 6.0EPSS 0.2%2024-05-30 - CVE-2023-45234CWE-119
Buffer Overflow in EDK II Network Package
High · CVSS 8.8EPSS 1.2%2024-01-16 - CVE-2023-45233CWE-835
Infinite loop in EDK II Network Package
High · CVSS 7.5EPSS 2.1%2024-01-16 - CVE-2023-45232CWE-835
Infinite loop in EDK II Network Package
High · CVSS 7.5EPSS 2.1%2024-01-16 - CVE-2023-45235CWE-119
Buffer Overflow in EDK II Network Package
High · CVSS 8.8EPSS 1.2%2024-01-16
Track new TianoCore CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor TianoCore CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the TianoCore CNA.
- What is the TianoCore CNA?
- TianoCore is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 27 CVE records since 2021.
- How many CVEs has TianoCore published?
- TianoCore has published 27 CVE records, including 8 in the last two years.
- What is TianoCore's CVE data quality grade?
- RadicalNotion.AI grades TianoCore's CVE data quality as A, with an overall completeness score of 91.7%. This reflects how consistently its CVE records include vendor (96.3%), product (100%), CVSS (77.8%), and CWE (92.6%) information.
- What products does TianoCore publish CVEs for?
- TianoCore most frequently publishes CVEs for EDK2, Azure Linux 3.0 x64, CBL Mariner 2.0 ARM, Azure Linux 3.0 ARM, CBL Mariner 2.0 x64.
- Which vendors does TianoCore cover?
- TianoCore publishes CVEs across 2 distinct vendors, most often TianoCore, Microsoft, Insyde.
- Is TianoCore actively publishing CVEs?
- TianoCore is currently active, based on 8 CVEs in the last two years.
- What is the average severity of TianoCore's CVEs?
- The average CVSS base score across TianoCore's scored CVEs is 6.7.
- How many critical CVEs has TianoCore published?
- TianoCore has published 1 critical-severity CVEs and 17 high-severity CVEs.
- Are any of TianoCore's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of TianoCore's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in TianoCore's CVEs?
- TianoCore's CVEs most often map to these CWE weakness types: CWE-122 (Heap-based Buffer Overflow), CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), CWE-125 (Out-of-bounds Read), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
- How does TianoCore rank among CNAs?
- By total CVE volume, TianoCore ranks #223 of 370 CNAs, and it reports more complete CVE records than 37% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track TianoCore CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.