Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.14%—AMD ProcessorsAI10/2/202617/6/2026
Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality.
AplazadaBaja (1.8)0.15%—AMD Secure ProcessorAI10/2/202617/6/2026
Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure.
AplazadaMedia (4.6)0.23%💥 PoCAMD CPUAI16/1/202617/6/2026
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.
AnalizadaMedia (5.5)0.11%—AMD Uprof24/11/202517/6/2026
Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service.
AnalizadaAlta (7.1)0.13%—AMD Uprof24/11/202517/6/2026
Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.
AnalizadaMedia (5.5)0.11%—AMD Uprof24/11/202530/9/2026
Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service
AplazadaAlta (7.3)0.14%—AMD StoremiAI23/11/202526/9/2026
Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AplazadaAlta (7.3)0.14%—AMD StoremiAI23/11/202526/9/2026
A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AplazadaAlta (7.2)0.17%—AMD CpusAI21/11/202517/6/2026
Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
AnalizadaMedia (5.5)0.11%—AMD Uprof21/11/202517/6/2026
Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.
AplazadaMedia (5.3)0.11%—AMD CPUAI21/11/202517/6/2026
A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
AplazadaMedia (6)0.21%—AMD Sev-snpAI14/10/202517/6/2026
Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.
AplazadaMedia (6.6)0.13%—AMD Zynq Ultrascale PlusAI6/10/202517/6/2026
In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality.
AplazadaAlta (7.2)0.15%—AMD CPUAI6/9/202517/6/2026
Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.
AplazadaBaja (3.3)0.19%—AMD Crash DefenderAI6/9/202517/6/2026
Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality.
AplazadaMedia (5.5)0.13%—AMD Crash DefenderAI6/9/202517/6/2026
A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentially resulting in a system crash and loss of availability.
AplazadaAlta (8.4)0.13%—AMD Graphics DriverAI6/9/202517/6/2026
Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service.
AplazadaMedia (6)0.13%—AMD Power Management FirmwareAI6/9/202517/6/2026
Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition.
AplazadaBaja (3.2)0.15%—AMD Sev-snpAI6/9/202517/6/2026
Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity.
AplazadaAlta (8.4)0.13%—AMD RomarmorAI6/9/202517/6/2026
Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, potentially resulting in a loss of confidentiality and integrity.
AplazadaMedia (4.4)0.14%—AMD Power Management FirmwareAIAMD AgesaAI6/9/202517/6/2026
Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
AplazadaBaja (3.3)0.13%—AMD Graphics DriverAI6/9/202517/6/2026
Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.
AplazadaAlta (7.9)0.17%—AMD TEEAI6/9/202517/6/2026
Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a command with malformed arguments leading to out of bounds memory access, potentially resulting in loss of integrity or availability.
AplazadaBaja (3.2)0.15%—Intel RdrandAIAMD SEV SNPAI5/9/202517/6/2026
Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.
AplazadaMedia (5.6)0.34%—AMD ProcessorsAI8/7/202517/6/2026
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.