Bootstrap OS
55 CVEs tracked. 3 of them are in CISA KEV.
This hub aggregates every CVE we track for Bootstrap OS, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Bootstrap OS CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 3 |
| 2024-11 | 0 |
| 2024-12 | 4 |
| 2025-01 | 2 |
| 2025-02 | 3 |
| 2025-03 | 2 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 55 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High16
- Medium26
- Low8
Latest CVEs
The 15 most recently published vulnerabilities affecting Bootstrap OS.
- CVE-2025-30691Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerabili...4.8
- CVE-2025-29768Vim vulnerable to potential data loss with zip.vim and special crafted zip files4.4
- CVE-2025-24813Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT9.8
- CVE-2025-1215vim main.c memory corruption2.8
- CVE-2025-0665eventfd double close9.8
- CVE-2025-0167netrc and default credential leak3.4
- CVE-2025-21502Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java ...4.8
- CVE-2025-22134heap-buffer-overflow with visual mode in Vim < 9.1.10034.2
- CVE-2024-56337Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete9.8
- CVE-2024-54677Apache Tomcat: DoS in examples web application5.3
- CVE-2024-50379Apache Tomcat: RCE due to TOCTOU issue in JSP compilation9.8
- CVE-2024-11053netrc and redirect credential leak3.4
- CVE-2024-21211Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java...3.7
- CVE-2024-9823Jetty DOS vulnerability on DosFilter5.3
- CVE-2024-47814use-after-free when closing buffers in Vim3.9
Product grouping is registry-driven, with AI assist and human review. How it works