Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
3
Current result set after filter and search.
Exploited Flagged
0
Rows with a non-empty exploitation signal.
Distinct CWE
3
Unique weakness classes in this view.
Modules
1
Unique inferred driver or component labels.
Reset
Active filters Module An Clear filters

Top Modules

1 modules
An3
Release Month
April 2026
1 CVE | last update 1 day(s) ago
Release 2026-04-18 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-70873
An
No latest release note
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2026-04-18 - -
Release Month
April 2024
1 CVE | last update 1 day(s) ago
Release 2024-04-15 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-3602
An
No latest release note
An information disclosure flaw was found in Buildah when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
2024-04-15 - -
Release Month
June 2021
1 CVE | last update 1 day(s) ago
Release 2021-06-10 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-3545
An
No latest release note
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized memory. A malicious guest could exploit this issue to leak memory from the host.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
2021-06-10 - -