Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | AMD Radeon Software | 15/11/2021 | 17/6/2026 | A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information. | |
| Modificada | Media (4.7) | 0.33% | — | AMD Athlon FirmwareAMD Athlon PRO FirmwareAMD Epyc FirmwareAMD Ryzen Firmware+1 | 13/10/2021 | 17/6/2026 | A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information. | |
| Modificada | Media (5.5) | 0.52% | — | AMD Chipset DriverAMD PSP Driver | 21/9/2021 | 17/6/2026 | An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages. | |
| Modificada | Alta (7.5) | 1.0% | — | AMD Epyc 7001 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7003 FirmwareAMD Epyc 7232p Firmware+57 | 11/6/2021 | 17/6/2026 | A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted. | |
| Modificada | Media (5.5) | 0.28% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass. | |
| Modificada | Alta (7.8) | 0.31% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading to escalation of privilege or denial of service. | |
| Modificada | Alta (7.8) | 0.26% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | |
| Modificada | Alta (7.8) | 0.26% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or denial of service. | |
| Modificada | Alta (7.8) | 0.26% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | |
| Modificada | Alta (7.8) | 0.28% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the driver, potentially causing memory corruptions in high privileged processes, which can lead to escalation of privileges or denial of service. | |
| Modificada | Alta (7.8) | 0.26% | — | AMD Radeon PRO SoftwareAMD Radeon Software | 11/6/2021 | 17/6/2026 | An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | |
| Modificada | Alta (7.2) | 1.7% | — | AMD Epyc 7232pAMD Epyc 7251AMD Epyc 7252AMD Epyc 7261+61 | 13/5/2021 | 17/6/2026 | In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server… | |
| Modificada | Alta (7.2) | 1.7% | — | AMD Epyc 7232pAMD Epyc 7251AMD Epyc 7252AMD Epyc 7261+61 | 13/5/2021 | 17/6/2026 | The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor. | |
| Modificada | Crítica (9.8) | 2.8% | — | Kramdown Project KramdownFedoraproject FedoraDebian Linux | 19/3/2021 | 17/6/2026 | Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. | |
| Modificada | Alta (7.8) | 0.35% | — | AMD Vbios Flash Tool Software Development KIT | 12/11/2020 | 17/6/2026 | A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system. | |
| Modificada | Media (6.4) | 0.21% | — | AMD Trusted Platform Modules Reference | 12/11/2020 | 17/6/2026 | The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power… | |
| Modificada | Media (5.5) | 0.47% | — | AMD Energy Driver FOR Linux | 12/11/2020 | 17/6/2026 | A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access. | |
| Modificada | Media (5.5) | 0.34% | — | AMD Atikmdag.sys | 13/10/2020 | 17/6/2026 | A denial of service vulnerability exists in the D3DKMTEscape handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTEscape API request can cause an out-of-bounds read in Windows OS kernel memory area. This vulnerability can be triggered from a non-privileged account. | |
| Modificada | Alta (7.8) | 1.3% | 💥 PoC | AMD Ryzen Master | 13/10/2020 | 17/6/2026 | A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system. | |
| Modificada | Media (5.5) | 0.34% | — | AMD Atikmdag.sys | 13/10/2020 | 17/6/2026 | A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTCreateAllocation API request can cause an out-of-bounds read and denial of service (BSOD). This vulnerability can be triggered from a… | |
| Modificada | Crítica (9.9) | 2.7% | — | AMD Radeon Directx 11 Driver Atidxx64.dll | 20/7/2020 | 17/6/2026 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest… | |
| Modificada | Crítica (9.9) | 2.7% | — | AMD Radeon Directx 11 Driver Atidxx64.dll | 20/7/2020 | 17/6/2026 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest… | |
| Modificada | Crítica (9.9) | 2.7% | — | AMD Radeon Directx 11 Driver Atidxx64.dll | 20/7/2020 | 17/6/2026 | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest… | |
| Modificada | Crítica (9.9) | 2.0% | — | AMD Radeon Directx 11 Driver Atidxx64.dll | 20/7/2020 | 17/6/2026 | An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver. A specially crafted pixel shader can cause memory corruption vulnerability. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability potentially could be… | |
| Modificada | Crítica (9.8) | 4.6% | — | Kramdown Project KramdownDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 17/7/2020 | 17/6/2026 | The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll,… |