Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.50%—Opensuse LeapOpensuse Tumbleweed Kopano-spamd29/6/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE…
ModificadaCrítica (9.8)2.1%—AMD Overdrive18/5/202017/6/2026
An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x81112ee0 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
ModificadaMedia (6.7)0.41%—AMD Atillk6418/5/202017/6/2026
An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. The vulnerable driver exposes a wrmsr instruction and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of…
ModificadaAlta (8.8)3.3%—AMD Atillk6427/4/202017/6/2026
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a…
ModificadaMedia (6.5)1.6%—Amcrest 1080-lite 8CH FirmwareAmcrest Amdv10814-h5 FirmwareAmcrest Ipm-721 FirmwareAmcrest Ip2m-841 Firmware+148/4/202017/6/2026
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.
AnalizadaAlta (8.8)36%⚠ Explotación activa💥 ExploitAmcrest 1080-lite 8CH FirmwareAmcrest Amdv10814-h5 FirmwareAmcrest Ipm-721 FirmwareAmcrest Ip2m-841 Firmware+148/4/202017/6/2026
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
ModificadaAlta (7.8)0.99%💥 PoCAMD User Experience Program12/2/202017/6/2026
The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary folder with an arbitrary file name.
ModificadaCrítica (9)1.8%—AMD Atidxx6425/1/202017/6/2026
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger…
ModificadaAlta (8.6)1.7%—AMD Atidxx6425/1/202017/6/2026
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest,…
ModificadaAlta (8.6)1.7%—AMD Atidxx6425/1/202017/6/2026
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13025.10004. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest,…
ModificadaAlta (8.6)1.7%—AMD Atidxx6425/1/202017/6/2026
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest,…
ModificadaAlta (7.5)0.94%—Spamdyke15/1/202016/6/2026
spamdyke prior to 4.2.1: STARTTLS reveals plaintext
ModificadaAlta (8.6)2.0%—Vmware WorkstationAMD Radeon RX 550 FirmwareAMD Radeon 550 Firmware5/12/201917/6/2026
An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware…
ModificadaCrítica (10)2.0%—AMD Radeon RX 550 FirmwareAMD Radeon 550 FirmwareAMD Radeon RX 550x Firmware31/10/201917/6/2026
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be…
AnalizadaMedia (5.5)0.25%—AMD Zu11eg FirmwareAMD Zu15eg FirmwareAMD Zu17eg FirmwareAMD Zu19eg Firmware+373/9/201917/6/2026
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.
ModificadaMedia (5.3)1.6%—AMD Secure Encrypted Virtualization FirmwareOpensuse Leap25/6/201917/6/2026
Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
ModificadaMedia (5.5)0.67%—HP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 FirmwareHP Proliant Xl750f Gen9 Server Firmware+973/12/201817/6/2026
The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the…
ModificadaAlta (7.1)0.43%—Hwinfo Amd64 Kernel Driver10/5/201817/6/2026
HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.
ModificadaMedia (5.5)0.55%💥 PoCHwinfo Amd64 Kernel Driver10/5/201817/6/2026
HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. This affects IOCTLs…
ModificadaCrítica (9)1.8%—AMD Ryzen Mobile FirmwareAMD Ryzen PRO FirmwareAMD Epyc Server FirmwareAMD Ryzen Firmware22/3/201817/6/2026
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
ModificadaCrítica (9)1.8%—AMD Ryzen PRO FirmwareAMD Ryzen Firmware22/3/201817/6/2026
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
ModificadaCrítica (9)1.8%—AMD Ryzen PRO FirmwareAMD Ryzen Firmware22/3/201817/6/2026
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.
ModificadaCrítica (9)1.7%—AMD Epyc Server Firmware22/3/201817/6/2026
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
ModificadaCrítica (9)1.7%—AMD Ryzen PRO FirmwareAMD Ryzen Firmware22/3/201817/6/2026
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZENFALL-4.
ModificadaCrítica (9)1.7%—AMD Ryzen Mobile FirmwareAMD Ryzen PRO FirmwareAMD Ryzen Firmware22/3/201817/6/2026
The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.