vciy

CVEs we hold for Microchip

Records whose assigning authority named Microchip as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-89172Side-channel attack of AN1044/AN953/SW300052 cryptographic algorithmsMicrochip SW300052
CVE-2026-3010TimePictra Stored Cross-Site ScriptingMicrochip TimePictra
CVE-2026-2844TimePictra Authentication Bypass VulnerabilityMicrochip TimePictra
CVE-2026-2336Weak webstax_auth Cookie Authentication Allows Privilege EscalationMicrochip IStaX
CVE-2026-18349SAMA5D44 Fault Injection VulnerabilityMicrochip SAMA5D4
CVE-2026-12622Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GNSS Time ServerMicrochip GridTime 3000
CVE-2026-12621Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTime™ 3000 GNSS Time ServerMicrochip GridTime 3000
CVE-2026-12620Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time ServerMicrochip GridTime 3000
CVE-2026-12619GridTime™ 3000 GNSS Time Server CSRF to XSSMicrochip GridTime 3000
CVE-2025-9497Hardcoded Upgrade Decryption PasswordsMicrochip Time Provider 4100
CVE-2025-47904Unsigned upgrade packageMicrochip Time Provider 4100
CVE-2025-47902SQL Injection in web resourceMicrochip Time Provider 4100
CVE-2025-47901RCE on restore configuration passwordMicrochip Time Provider 4100
CVE-2025-47900RCE on backup configuration passwordMicrochip Time Provider 4100
CVE-2024-9054Remote code Execution inTimeProvider® 4100Microchip TimeProvider 4100
CVE-2024-7801SQL injection in get_chart_data in TimeProvider 4100Microchip TimeProvider 4100
CVE-2024-7490Remote Code Execution in Advanced Software Framework DHCP serverMicrochip Techology Advanced Software Framework
CVE-2024-4760Voltage glitch during startup of the EEFC NVM controller can bypass the security bitMicrochip SAM3U
CVE-2024-43687XSS vulnerability in bannerconfig endpoint in TimeProvider 4100Microchip TimeProvider 4100
CVE-2024-43686Reflected XSS in TimeProvider 4100 chart componentMicrochip TimeProvider 4100
CVE-2024-43685Session token fixation in TimeProvider 4100Microchip TimeProvider 4100
CVE-2024-43684Cross-Site Request Forgery vulnerability in TimeProvider 4100Microchip TimeProvider 4100
CVE-2024-43683Improper verification of the Host header in TimeProvider 4100Microchip TimeProvider 4100
CVE-2024-30212Microchip Harmony 3 Core library allows read and write access to RAM via a SCSI READ or WRITE commandMicrochip MPLAB® Harmony 3 Core Module
CVE-2024-29155Denial of service on Microchip RN4870 devicesMicrochip RN4870

25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.