CVE Feed

Recent embedded-target CVEs

CVEs published in the last 168 hours that match an embedded/firmware target BootIntel covers: bootloaders (U-Boot, coreboot, TF-A, OpenSBI), embedded TLS (OpenSSL, Mbed TLS, wolfSSL), common daemons (dnsmasq, hostapd, wpa_supplicant, Dropbear), and distros/toolchains (OpenWrt, Buildroot, ESP-IDF, Tasmota, MediaTek). Severity ≥ MEDIUM. Refreshed every 4 hours from NVD.

0 entriesupdated neverRSSJSON Feed

No CVEs in the current 168-hour window match a covered target. Check back after the next refresh cycle.

Why this exists. The same filter that picks a CVE for the daily @bootintel.bsky.social post catches ~15 matches per cycle: the Bluesky account only shows one. This page publishes the rest, plus the ones already posted, so you can subscribe and monitor without a Bluesky account.

How to use it. Point your feed reader at the RSS or JSON Feed URL. Scripts and automation should pull JSON: it includes CVSS scores and target labels in the per-item _bootintel block. Feed data derives from NVD and matches BootIntel's target keyword list, see coverage for the full detector inventory.