Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.11%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.
Pendiente de análisisMedia (5.8)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality.
Pendiente de análisisAlta (8.4)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality.
Pendiente de análisisAlta (8.4)0.11%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability.
Pendiente de análisisAlta (8.3)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability.
Pendiente de análisisAlta (8.6)0.11%—AMD Raid DriverAI15/5/202617/6/2026
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution.
Pendiente de análisisAlta (8.8)0.10%—AMD Secure ProcessorAI15/5/202617/6/2026
Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.
Pendiente de análisisAlta (7.1)0.10%—AMD Secure ProcessorAIAMD Video Core NextAI15/5/202617/6/2026
Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next (VCN) firmware potentially impacting…
Pendiente de análisisMedia (6.8)0.11%—AMD Power Management FirmwareAI15/5/202617/6/2026
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability.
Pendiente de análisisAlta (8.5)0.10%—AMD Chipset DriverAI15/5/202617/6/2026
Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
Pendiente de análisisAlta (8.5)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.
Pendiente de análisisMedia (6.9)0.10%—AMD Secure Processor PCI DriverAI15/5/202617/6/2026
Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash.
Pendiente de análisisMedia (6.9)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash
Pendiente de análisisAlta (8.5)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation
Pendiente de análisisAlta (7)0.11%—AMD General-purpose Input Output ControllerAI15/5/202617/6/2026
Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.
Pendiente de análisisMedia (6.9)0.11%—AMD Secure Processor PCI DriverAI15/5/202617/6/2026
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service
Pendiente de análisisMedia (4.6)0.11%—AMD OverdriveAI15/5/202617/6/2026
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.
Pendiente de análisisAlta (7)0.11%—AMD Optional ToolsAIOpensslAI14/5/202617/6/2026
Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially resulting in arbitrary code execution.
Pendiente de análisisAlta (8.5)0.13%—AMD Secure ProcessorAIAMD SEV SNPAI13/5/202617/6/2026
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.
Pendiente de análisisBaja (2)0.19%💥 PoCAMD CPUAI27/4/202617/6/2026
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
Pendiente de análisisAlta (7.1)0.14%—AMD Platform Configuration BlobAI16/4/202615/7/2026
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.
Pendiente de análisisMedia (5.9)0.11%—AMD Secure Processor FirmwareAIAMD ZEN 5AI16/4/202617/6/2026
A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.
ModificadaCrítica (9.8)2.6%💥 PoCLodashLodash-amdLodash-esLodash.template31/3/202610/9/2026
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as…
AnalizadaMedia (5.3)0.38%—LodashLodash-amdLodash-esLodash.unset31/3/202624/7/2026
Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing…
AplazadaAlta (8.6)0.18%—River Past CamdoAIRiver Past Lame ENCAI26/3/202617/6/2026
River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and SEH handler address…