Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.27% | — | AMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 FirmwareAMD Epyc 7663 Firmware+19 | 10/5/2022 | 17/6/2026 | A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs. | |
| Modificada | Crítica (9.1) | 1.4% | — | Ramdajs Ramda | 10/5/2022 | 17/6/2026 | Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only… | |
| Modificada | Media (5.6) | 0.29% | — | AMD Athlon X4 940 FirmwareAMD Athlon X4 950 FirmwareAMD Athlon X4 970 FirmwareAMD Athlon X4 835 Firmware+122 | 11/3/2022 | 17/6/2026 | LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. | |
| Modificada | Media (6.5) | 0.32% | — | AMD Athlon X4 940 FirmwareAMD Athlon X4 950 FirmwareAMD Athlon X4 970 FirmwareAMD Athlon X4 835 Firmware+122 | 11/3/2022 | 17/6/2026 | Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage. | |
| Modificada | Media (6.8) | 0.19% | — | AMD Xilinx Z-7012s FirmwareAMD Xilinx Z-7014s FirmwareAMD Xilinx Z-7010 FirmwareAMD Xilinx Z-7015 Firmware+6 | 10/2/2022 | 17/6/2026 | On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the boot header stored on an SD card so that a secure image appears to be… | |
| Modificada | Media (5.5) | 0.31% | — | AMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 FirmwareAMD Epyc 7663 Firmware+103 | 4/2/2022 | 17/6/2026 | AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by… | |
| Modificada | Alta (7.5) | 2.4% | — | AMD Ryzen PRO 5650g FirmwareAMD Ryzen PRO 5650ge FirmwareAMD Ryzen PRO 5750g FirmwareAMD Ryzen PRO 5750ge Firmware+59 | 4/2/2022 | 17/6/2026 | When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage. | |
| Modificada | Alta (7.8) | 0.25% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 4/2/2022 | 17/6/2026 | AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable. | |
| Modificada | Alta (8.4) | 0.25% | — | AMD Epyc 7001 FirmwareAMD Epyc 7232p FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 Firmware+101 | 10/12/2021 | 17/6/2026 | A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM). | |
| Modificada | Media (6.7) | 0.29% | — | AMD Generic Encapsulated Software Architecture | 10/12/2021 | 17/6/2026 | Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system. | |
| Modificada | Crítica (9.9) | 1.2% | — | AMD Uprof | 1/12/2021 | 17/6/2026 | The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user. | |
| Modificada | Media (5.5) | 0.24% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 Firmware+108 | 16/11/2021 | 17/6/2026 | Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests. | |
| Modificada | Media (5.5) | 0.22% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 Firmware+91 | 16/11/2021 | 17/6/2026 | Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components. | |
| Modificada | Alta (7.8) | 0.29% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7001 FirmwareAMD Epyc 72f3 Firmware+54 | 16/11/2021 | 17/6/2026 | Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.29% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7001 FirmwareAMD Epyc 72f3 Firmware+54 | 16/11/2021 | 17/6/2026 | AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.22% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7001 FirmwareAMD Epyc 72f3 Firmware+54 | 16/11/2021 | 17/6/2026 | AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources. | |
| Modificada | Media (5.5) | 0.24% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+16 | 16/11/2021 | 17/6/2026 | Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality. | |
| Modificada | Media (5.5) | 0.22% | — | AMD Epyc 7232p FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+16 | 16/11/2021 | 17/6/2026 | Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service. | |
| Modificada | Alta (7.8) | 0.25% | — | AMD Epyc 7232p FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+16 | 16/11/2021 | 17/6/2026 | Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity. | |
| Modificada | Media (5.5) | 0.25% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. | |
| Modificada | Media (5.5) | 0.19% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP | |
| Modificada | Alta (7.8) | 0.17% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+16 | 16/11/2021 | 17/6/2026 | When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used. | |
| Modificada | Alta (7.8) | 0.25% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 Firmware+41 | 16/11/2021 | 17/6/2026 | A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections. | |
| Modificada | Media (5.5) | 0.23% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7001 FirmwareAMD Epyc 72f3 Firmware+54 | 16/11/2021 | 17/6/2026 | A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification. | |
| Modificada | Alta (7) | 0.22% | — | AMD Epyc 7003 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7001 FirmwareAMD Epyc 72f3 Firmware+54 | 16/11/2021 | 17/6/2026 | Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations. |