Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.14% | — | AMD ProcessorsAI | 10/2/2026 | 17/6/2026 | Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality. | |
| Aplazada | Baja (1.8) | 0.15% | — | AMD Secure ProcessorAI | 10/2/2026 | 17/6/2026 | Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure. | |
| Aplazada | Media (4.6) | 0.23% | 💥 PoC | AMD CPUAI | 16/1/2026 | 17/6/2026 | Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest. | |
| Analizada | Media (5.5) | 0.11% | — | AMD Uprof | 24/11/2025 | 17/6/2026 | Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service. | |
| Analizada | Alta (7.1) | 0.13% | — | AMD Uprof | 24/11/2025 | 17/6/2026 | Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability. | |
| Analizada | Media (5.5) | 0.11% | — | AMD Uprof | 24/11/2025 | 30/9/2026 | Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service | |
| Aplazada | Alta (7.3) | 0.14% | — | AMD StoremiAI | 23/11/2025 | 26/9/2026 | Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.3) | 0.14% | — | AMD StoremiAI | 23/11/2025 | 26/9/2026 | A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.2) | 0.17% | — | AMD CpusAI | 21/11/2025 | 17/6/2026 | Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values. | |
| Analizada | Media (5.5) | 0.11% | — | AMD Uprof | 21/11/2025 | 17/6/2026 | Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service. | |
| Aplazada | Media (5.3) | 0.11% | — | AMD CPUAI | 21/11/2025 | 17/6/2026 | A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity. | |
| Aplazada | Media (6) | 0.21% | — | AMD Sev-snpAI | 14/10/2025 | 17/6/2026 | Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity. | |
| Aplazada | Media (6.6) | 0.13% | — | AMD Zynq Ultrascale PlusAI | 6/10/2025 | 17/6/2026 | In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality. | |
| Aplazada | Alta (7.2) | 0.15% | — | AMD CPUAI | 6/9/2025 | 17/6/2026 | Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution. | |
| Aplazada | Baja (3.3) | 0.19% | — | AMD Crash DefenderAI | 6/9/2025 | 17/6/2026 | Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in loss of confidentiality. | |
| Aplazada | Media (5.5) | 0.13% | — | AMD Crash DefenderAI | 6/9/2025 | 17/6/2026 | A NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentially resulting in a system crash and loss of availability. | |
| Aplazada | Alta (8.4) | 0.13% | — | AMD Graphics DriverAI | 6/9/2025 | 17/6/2026 | Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service. | |
| Aplazada | Media (6) | 0.13% | — | AMD Power Management FirmwareAI | 6/9/2025 | 17/6/2026 | Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition. | |
| Aplazada | Baja (3.2) | 0.15% | — | AMD Sev-snpAI | 6/9/2025 | 17/6/2026 | Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity. | |
| Aplazada | Alta (8.4) | 0.13% | — | AMD RomarmorAI | 6/9/2025 | 17/6/2026 | Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a standby state, potentially resulting in a loss of confidentiality and integrity. | |
| Aplazada | Media (4.4) | 0.14% | — | AMD Power Management FirmwareAIAMD AgesaAI | 6/9/2025 | 17/6/2026 | Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity. | |
| Aplazada | Baja (3.3) | 0.13% | — | AMD Graphics DriverAI | 6/9/2025 | 17/6/2026 | Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability. | |
| Aplazada | Alta (7.9) | 0.17% | — | AMD TEEAI | 6/9/2025 | 17/6/2026 | Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised userspace to invoke a command with malformed arguments leading to out of bounds memory access, potentially resulting in loss of integrity or availability. | |
| Aplazada | Baja (3.2) | 0.15% | — | Intel RdrandAIAMD SEV SNPAI | 5/9/2025 | 17/6/2026 | Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests. | |
| Aplazada | Media (5.6) | 0.34% | — | AMD ProcessorsAI | 8/7/2025 | 17/6/2026 | A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries. |