Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
Docs
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
trusted computing group vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2025-2884
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0
Trusted Computing Group Tpm2.0
7.8
CVSSv3
CVE-2023-1017
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashin...
Trusted Computing Group Tpm2.0
Trustedcomputinggroup Trusted Platform Module 2.0
Microsoft Windows 10 1507
Microsoft Windows 10 1607
Microsoft Windows 10 1809
Microsoft Windows 10 20h2
Microsoft Windows 10 21h2
Microsoft Windows 10 22h2
Microsoft Windows 11 21h2
Microsoft Windows 11 22h2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
2 Github repositories
1 Article
5.5
CVSSv3
CVE-2023-1018
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the ...
Trusted Computing Group Tpm2.0
Trustedcomputinggroup Trusted Platform Module 2.0
Microsoft Windows 10 1507
Microsoft Windows 10 1607
Microsoft Windows 10 1809
Microsoft Windows 10 20h2
Microsoft Windows 10 21h2
Microsoft Windows 10 22h2
Microsoft Windows 11 21h2
Microsoft Windows 11 22h2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
2 Github repositories
1 Article
6
CVSSv3
CVE-2020-26933
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 up to and including 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in su...
Trustedcomputinggroup Trusted Platform Module 2.0
7.1
CVSSv3
CVE-2018-6622
An issue exists that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 s...
Trustedcomputinggroup Trusted Platform Module 2.0
1 Github repository
6.4
CVSSv3
CVE-2023-22745
tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In affected versions `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array ...
Tpm2-software Tpm2-tss
Tpm2 Software Stack Project Tpm2 Software Stack
5.9
CVSSv3
CVE-2025-49133
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulner...
Stefanberger Libtpms
10
CVSSv3
CVE-2021-44228
Apache Log4j2 2.0-beta9 up to and including 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can contr...
Apache Software Foundation Apache Log4j2
Siemens 6bk1602-0aa12-0tp0 Firmware
Siemens 6bk1602-0aa22-0tp0 Firmware
Siemens 6bk1602-0aa32-0tp0 Firmware
Siemens 6bk1602-0aa42-0tp0 Firmware
Siemens 6bk1602-0aa52-0tp0 Firmware
Apache Log4j
Apache Log4j 2.0
Siemens Sppa-t3000 Ses3000 Firmware
Siemens Capital
Siemens Capital 2019.1
Siemens Comos
2 Metasploit modules
881 Github repositories
29 Articles
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
inject
CVE-2025-51381
IDOR
nvidia
CVE-2025-4123
CVE-2025-2783
CVE-2025-30678
remote attackers
CVE-2025-48443
kcm3100
CVE-2025-6196
tarteaucitron.io
adrian ladó
earch icon">CVE-2023-33538
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started