Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

trustedfirmware

About This Vendor

trustedfirmware is a technology vendor producing software and infrastructure products. As a software provider, trustedfirmware's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of trustedfirmware's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 76 known vulnerabilities from trustedfirmware. This includes 18 critical-severity issues and 30 high-severity issues that represent significant risk. These vulnerabilities affect 66 distinct products across trustedfirmware's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2015 through 2026, indicating decades of continuous security attention and research. Organizations deploying trustedfirmware products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2015-5291 2015-11-02 2026-06-05 - 6.8 Likely
CVE-2015-8036 2015-11-02 2026-06-05 - 6.8 Likely
CVE-2016-6129 2017-02-13 2026-06-05 7.5 5.0 Likely
CVE-2017-2784 2017-04-20 2026-06-05 8.1 6.8 Likely
CVE-2017-7563 2017-06-07 2026-06-08 8.1 6.8 Likely
CVE-2017-7564 2017-06-07 2026-06-08 7.5 5.0 Likely
CVE-2017-14032 2017-08-30 2026-06-05 8.1 6.8 Likely
CVE-2017-9607 2017-09-20 2026-06-05 7.0 5.1 Unknown
CVE-2018-9988 2018-04-10 2026-06-05 7.5 5.0 Likely
CVE-2018-9989 2018-04-10 2026-06-05 7.5 5.0 Likely
CVE-2018-12437 2018-06-15 2026-06-05 4.9 1.9 Unknown
CVE-2018-19608 2018-12-05 2026-06-05 4.7 1.9 Unknown
CVE-2017-15031 2018-12-18 2026-06-05 7.5 5.0 Likely
CVE-2018-19440 2019-01-30 2026-06-05 5.3 5.0 Likely
CVE-2019-1010293 2019-07-15 2026-06-05 9.8 7.5 Likely
CVE-2019-1010294 2019-07-15 2026-06-05 7.5 5.0 Likely
CVE-2019-1010295 2019-07-15 2026-06-05 9.8 7.5 Likely
CVE-2019-1010296 2019-07-15 2026-06-05 9.8 10.0 Likely
CVE-2019-1010297 2019-07-15 2026-06-05 9.8 10.0 Likely
CVE-2019-1010298 2019-07-15 2026-06-05 9.8 10.0 Likely
CVE-2019-1010292 2019-07-16 2026-06-05 9.8 7.5 Likely
CVE-2019-16910 2019-09-26 2026-06-05 5.3 2.6 Unknown
CVE-2020-10932 2020-04-15 2026-06-05 4.7 1.9 Unknown
CVE-2020-13799 2020-11-18 2026-06-05 6.8 4.6 Unknown
CVE-2021-32032 2021-05-21 2026-06-08 7.5 5.0 Likely
CVE-2021-27562 2021-05-25 2026-06-05 5.5 4.9 Unknown
CVE-2019-25052 2021-08-11 2026-06-05 9.1 6.4 Likely
CVE-2021-36133 2021-12-07 2026-06-05 7.1 3.6 Unknown
CVE-2021-44149 2021-12-07 2026-06-05 7.8 4.6 Unknown
CVE-2021-44732 2021-12-20 2026-06-05 9.8 7.5 Likely
CVE-2021-45450 2021-12-21 2026-06-05 7.5 5.0 Likely
CVE-2021-40327 2022-01-13 2026-06-05 5.9 2.6 Unknown
CVE-2021-43619 2022-03-01 2026-06-05 7.8 4.6 Unknown
CVE-2022-35409 2022-07-15 2026-06-05 9.1 - -
CVE-2022-46152 2022-11-29 2026-06-05 8.2 - -
CVE-2022-46392 2022-12-15 2026-06-05 5.3 - -
CVE-2022-46393 2022-12-15 2026-06-05 9.8 - -
CVE-2022-47549 2022-12-19 2026-06-05 6.4 - -
CVE-2022-47630 2023-01-16 2026-06-05 7.4 - -
CVE-2021-36647 2023-01-17 2026-06-05 4.7 - -
CVE-2023-40271 2023-09-08 2026-06-05 7.5 - -
CVE-2023-41325 2023-09-15 2026-06-05 7.4 - -
CVE-2023-43615 2023-10-07 2026-06-05 7.5 - -
CVE-2023-45199 2023-10-07 2026-06-05 9.8 - -
CVE-2024-23744 2024-01-21 2026-06-05 7.5 - -
CVE-2024-23170 2024-01-31 2026-06-05 5.5 - -
CVE-2024-23775 2024-01-31 2026-06-05 7.5 - -
CVE-2024-28960 2024-03-29 2026-06-05 8.2 - -
CVE-2024-28755 2024-04-03 2026-06-05 6.5 - -
CVE-2024-28836 2024-04-03 2026-06-05 5.4 - -
CVE-2024-30166 2024-04-03 2026-06-05 9.1 - -
CVE-2023-31339 2024-08-13 2026-06-05 4.8 - -
CVE-2023-51712 2024-09-05 2026-06-05 4.7 - -
CVE-2024-45157 2024-09-05 2026-06-05 5.1 - -
CVE-2024-45158 2024-09-05 2026-06-05 9.8 - -
CVE-2024-45159 2024-09-05 2026-06-05 9.8 - -
CVE-2024-49195 2024-10-15 2026-06-05 9.8 - -
CVE-2025-27809 2025-03-25 2026-06-05 5.4 - -
CVE-2025-27810 2025-03-25 2026-06-05 5.4 - -
CVE-2025-49600 2025-07-04 2026-06-05 4.9 - -
CVE-2025-49601 2025-07-04 2026-06-05 4.8 - -
CVE-2025-49087 2025-07-20 2026-06-05 4.0 - -
CVE-2026-25834 2026-04-01 2026-06-05 6.5 - -
CVE-2026-34875 2026-04-01 2026-06-05 9.8 - -
CVE-2026-25833 2026-04-01 2026-06-05 7.5 - -
CVE-2026-25835 2026-04-01 2026-06-05 7.7 - -
CVE-2026-34871 2026-04-01 2026-06-05 6.7 - -
CVE-2026-34874 2026-04-01 2026-06-05 7.5 - -
CVE-2026-34873 2026-04-01 2026-06-05 9.1 - -
CVE-2026-34876 2026-04-02 2026-06-05 7.5 - -
CVE-2026-34877 2026-04-02 2026-06-05 9.8 - -
CVE-2026-33317 2026-04-24 2026-06-05 8.7 - -
CVE-2026-33662 2026-04-24 2026-06-05 7.5 - -
CVE-2026-40290 2026-06-03 2026-06-05 7.8 - -
CVE-2026-45614 2026-06-03 2026-06-05 4.7 - -
CVE-2026-45702 2026-06-03 2026-06-05 4.4 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for trustedfirmware by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with trustedfirmware's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.