Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.22% | — | AMD Integrated Management TechnologyAI | 11/2/2025 | 17/6/2026 | Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (7.2) | 0.53% | — | AMD CPU ROM Microcode Patch LoaderAI | 3/2/2025 | 17/6/2026 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. | |
| Analizada | Alta (7.8) | 0.27% | — | AMD Ryzen AI Software | 12/11/2024 | 17/6/2026 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution. | |
| Analizada | Alta (7.8) | 0.27% | — | AMD Ryzen AI Software | 12/11/2024 | 17/6/2026 | Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.27% | — | AMD Provisioning Console | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.27% | — | AMD Management Console | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Media (5.5) | 0.22% | — | AMD Ryzen AI Software | 12/11/2024 | 17/6/2026 | Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash. | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Utility FOR Overclocking Control | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Monitoring Software Development KIT | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.3) | 0.23% | — | AMD Cloud Manageability Service | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.8) | 0.22% | — | AMD Management Plugin FOR Sccm | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Analizada | Alta (7.8) | 0.26% | — | AMD Radeon SoftwareAMD Radeon Software FOR HIP | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Analizada | Media (5.4) | 0.26% | — | Essamamdani Advanced Blocks PRO | 10/10/2024 | 17/6/2026 | The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Alta (8.2) | 0.20% | — | Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+16 | 28/8/2024 | 17/6/2026 | Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution. | |
| Aplazada | Media (5.7) | 0.14% | — | AMD Secure ProcessorAI | 13/8/2024 | 17/6/2026 | Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity. | |
| Modificada | Media (5.5) | 0.15% | — | AMD Uprof | 13/8/2024 | 17/6/2026 | Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service. | |
| Aplazada | Media (4.4) | 0.21% | — | AMD SEV FirmwareAI | 13/8/2024 | 17/6/2026 | Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity. | |
| Modificada | Alta (7.8) | 0.16% | — | AMD Uprof | 13/8/2024 | 17/6/2026 | Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.18% | — | AMD Uprof | 13/8/2024 | 17/6/2026 | A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Modificada | Media (5.5) | 0.13% | — | AMD Uprof | 13/8/2024 | 17/6/2026 | Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service. | |
| Analizada | Media (5.8) | 0.16% | — | AMD Trusted Firmware-aTrustedfirmware Trusted Firmware-a | 13/8/2024 | 17/6/2026 | Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service. | |
| Aplazada | Media (5) | 0.14% | — | AMD Power Management FirmwareAI | 13/8/2024 | 17/6/2026 | Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability. | |
| Analizada | Media (4.4) | 0.15% | — | AMD Radeon Software | 13/8/2024 | 17/6/2026 | Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service. | |
| Modificada | Crítica (10) | 0.30% | — | AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+61 | 13/8/2024 | 17/6/2026 | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability. | |
| Analizada | Media (6) | 0.19% | — | AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+61 | 13/8/2024 | 17/6/2026 | IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity. |