Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.14%—AMD Video Decoder Engine FirmwareAI12/2/202617/6/2026
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
AplazadaAlta (8.4)0.14%—AMD Secure ProcessorAI12/2/202617/6/2026
Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability.
AplazadaAlta (7.2)0.10%—AMD Power Management FirmwareAI12/2/202617/6/2026
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
AplazadaAlta (7)0.14%—AMD UprofAI11/2/202617/6/2026
Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AplazadaMedia (6.9)0.14%—AMD Graphics DriverAI11/2/202617/6/2026
Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.
AplazadaAlta (7.8)0.14%—AMD Software InstallerAI11/2/202617/6/2026
A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AplazadaAlta (8.8)0.17%—AMD Graphics DriverAI11/2/202617/6/2026
Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution.
AplazadaAlta (7)0.14%—AMD Atihdwt6AI11/2/202617/6/2026
Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentiality, integrity and availability
AplazadaMedia (5.5)0.16%—AMD Graphics DriverAI11/2/202617/6/2026
The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service
AnalizadaAlta (7.1)0.11%—AMD RocmAMD Radeon SoftwareAMD Radeon PRO VII FirmwareAMD Radeon VII Firmware11/2/202617/6/2026
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.
AnalizadaAlta (7.1)0.11%—AMD RocmAMD Radeon SoftwareAMD Radeon VII FirmwareAMD Radeon PRO VII Firmware11/2/202617/6/2026
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
AplazadaAlta (8.7)0.15%—AMD Secure ProcessorAI11/2/202617/6/2026
Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in arbitrary code execution
AplazadaMedia (6.7)0.14%—AMD SEV FirmwareAI10/2/202617/6/2026
Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity.
AplazadaMedia (5.3)0.32%—AMD CPU MicrocodeAI10/2/202617/6/2026
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.
AplazadaMedia (4.6)0.14%—AMD SEV FirmwareAIAMD Sev-esAIAMD Sev-snpAI10/2/202617/6/2026
Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of confidentiality.
AplazadaMedia (5.4)0.13%—AMD Secure ProcessorAI10/2/202617/6/2026
Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution.
AplazadaMedia (4)0.14%—AMD SEV FirmwareAI10/2/202617/6/2026
Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.
AplazadaMedia (5.9)0.15%—AMD Secure Encrypted VirtualizationAI10/2/202617/6/2026
Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity
AplazadaAlta (7.3)0.14%—AMD Secure ProcessorAI10/2/202617/6/2026
A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution.
AplazadaMedia (4.8)0.14%—AMD Secure ProcessorAI10/2/202617/6/2026
Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service.
AplazadaMedia (5.9)0.15%—AMD Secure Encrypted VirtualizationAI10/2/202617/6/2026
Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.
AplazadaMedia (4.5)0.15%—AMD SEV FirmwareAI10/2/202617/6/2026
Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.
AplazadaMedia (6.9)0.14%—AMD SEVAI10/2/202617/6/2026
Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity.
AplazadaMedia (4.6)0.12%—AMD SEV FirmwareAI10/2/202617/6/2026
A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.
AplazadaBaja (1.8)0.12%—AMD Sev-snpAI10/2/202617/6/2026
Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity