Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution. | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability. | |
| Pendiente de análisis | Alta (8.3) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability. | |
| Pendiente de análisis | Alta (8.6) | 0.11% | — | AMD Raid DriverAI | 15/5/2026 | 17/6/2026 | Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.10% | — | AMD Secure ProcessorAI | 15/5/2026 | 17/6/2026 | Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | AMD Secure ProcessorAIAMD Video Core NextAI | 15/5/2026 | 17/6/2026 | Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next (VCN) firmware potentially impacting… | |
| Pendiente de análisis | Media (6.8) | 0.11% | — | AMD Power Management FirmwareAI | 15/5/2026 | 17/6/2026 | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Chipset DriverAI | 15/5/2026 | 17/6/2026 | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation | |
| Pendiente de análisis | Alta (7) | 0.11% | — | AMD General-purpose Input Output ControllerAI | 15/5/2026 | 17/6/2026 | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | AMD Secure Processor PCI DriverAI | 15/5/2026 | 17/6/2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service | |
| Pendiente de análisis | Media (4.6) | 0.11% | — | AMD OverdriveAI | 15/5/2026 | 17/6/2026 | Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality. | |
| Pendiente de análisis | Alta (7) | 0.11% | — | AMD Optional ToolsAIOpensslAI | 14/5/2026 | 17/6/2026 | Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (8.5) | 0.13% | — | AMD Secure ProcessorAIAMD SEV SNPAI | 13/5/2026 | 17/6/2026 | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity. | |
| Pendiente de análisis | Baja (2) | 0.19% | 💥 PoC | AMD CPUAI | 27/4/2026 | 17/6/2026 | A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality. | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | AMD Platform Configuration BlobAI | 16/4/2026 | 15/7/2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Media (5.9) | 0.11% | — | AMD Secure Processor FirmwareAIAMD ZEN 5AI | 16/4/2026 | 17/6/2026 | A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | LodashLodash-amdLodash-esLodash.template | 31/3/2026 | 10/9/2026 | Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as… | |
| Analizada | Media (5.3) | 0.38% | — | LodashLodash-amdLodash-esLodash.unset | 31/3/2026 | 24/7/2026 | Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing… | |
| Aplazada | Alta (8.6) | 0.18% | — | River Past CamdoAIRiver Past Lame ENCAI | 26/3/2026 | 17/6/2026 | River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and SEH handler address… |