Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.14% | — | AMD Video Decoder Engine FirmwareAI | 12/2/2026 | 17/6/2026 | Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system. | |
| Aplazada | Alta (8.4) | 0.14% | — | AMD Secure ProcessorAI | 12/2/2026 | 17/6/2026 | Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability. | |
| Aplazada | Alta (7.2) | 0.10% | — | AMD Power Management FirmwareAI | 12/2/2026 | 17/6/2026 | An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7) | 0.14% | — | AMD UprofAI | 11/2/2026 | 17/6/2026 | Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Aplazada | Media (6.9) | 0.14% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service. | |
| Aplazada | Alta (7.8) | 0.14% | — | AMD Software InstallerAI | 11/2/2026 | 17/6/2026 | A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (8.8) | 0.17% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary code execution. | |
| Aplazada | Alta (7) | 0.14% | — | AMD Atihdwt6AI | 11/2/2026 | 17/6/2026 | Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentiality, integrity and availability | |
| Aplazada | Media (5.5) | 0.16% | — | AMD Graphics DriverAI | 11/2/2026 | 17/6/2026 | The integer overflow vulnerability within AMD Graphics driver could allow an attacker to bypass size checks potentially resulting in a denial of service | |
| Analizada | Alta (7.1) | 0.11% | — | AMD RocmAMD Radeon SoftwareAMD Radeon PRO VII FirmwareAMD Radeon VII Firmware | 11/2/2026 | 17/6/2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability. | |
| Analizada | Alta (7.1) | 0.11% | — | AMD RocmAMD Radeon SoftwareAMD Radeon VII FirmwareAMD Radeon PRO VII Firmware | 11/2/2026 | 17/6/2026 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability. | |
| Aplazada | Alta (8.7) | 0.15% | — | AMD Secure ProcessorAI | 11/2/2026 | 17/6/2026 | Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environment resulting in arbitrary code execution | |
| Aplazada | Media (6.7) | 0.14% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity. | |
| Aplazada | Media (5.3) | 0.32% | — | AMD CPU MicrocodeAI | 10/2/2026 | 17/6/2026 | Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity. | |
| Aplazada | Media (4.6) | 0.14% | — | AMD SEV FirmwareAIAMD Sev-esAIAMD Sev-snpAI | 10/2/2026 | 17/6/2026 | Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of confidentiality. | |
| Aplazada | Media (5.4) | 0.13% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution. | |
| Aplazada | Media (4) | 0.14% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality. | |
| Aplazada | Media (5.9) | 0.15% | — | AMD Secure Encrypted VirtualizationAI | 10/2/2026 | 17/6/2026 | Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP covered memory, potentially resulting in loss of guest memory integrity | |
| Aplazada | Alta (7.3) | 0.14% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution. | |
| Aplazada | Media (4.8) | 0.14% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service. | |
| Aplazada | Media (5.9) | 0.15% | — | AMD Secure Encrypted VirtualizationAI | 10/2/2026 | 17/6/2026 | Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity. | |
| Aplazada | Media (4.5) | 0.15% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory. | |
| Aplazada | Media (6.9) | 0.14% | — | AMD SEVAI | 10/2/2026 | 17/6/2026 | Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity. | |
| Aplazada | Media (4.6) | 0.12% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity. | |
| Aplazada | Baja (1.8) | 0.12% | — | AMD Sev-snpAI | 10/2/2026 | 17/6/2026 | Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity |