Products: 214
    Vulnerabilities: 21
    Known Exploited: 0
    1
    Critical Level Threats
    9
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-29338

    NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_para parameter in the woal_init_module_param function.

    Last Modified: May 17, 2026
    Published: May 13, 2026

    CVE-2023-39902

    A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing unauthenticated software to execute on the target, leading to privilege escalation. This affects i.MX 8M, i.MX 8M Mini, i.MX 8M Nano, and i.MX 8M Plus.

    Last Modified: Nov 21, 2024
    Published: Oct 17, 2023

    CVE-2022-45163

    An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)

    Last Modified: Apr 30, 2025
    Published: Nov 18, 2022

    CVE-2021-22680

    NXP MQX Integer Overflow or Wraparound

    Last Modified: Apr 16, 2025
    Published: May 03, 2022

    CVE-2021-27421

    NXP MCUXpresso SDK Integer Overflow or Wraparound

    Last Modified: Apr 16, 2025
    Published: May 03, 2022
    Items Per Page