Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.22%—AMD Integrated Management TechnologyAI11/2/202517/6/2026
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AplazadaAlta (7.2)0.53%—AMD CPU ROM Microcode Patch LoaderAI3/2/202517/6/2026
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
AnalizadaAlta (7.8)0.27%—AMD Ryzen AI Software12/11/202417/6/2026
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
AnalizadaAlta (7.8)0.27%—AMD Ryzen AI Software12/11/202417/6/2026
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
AnalizadaAlta (7.3)0.27%—AMD Provisioning Console12/11/202417/6/2026
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AnalizadaAlta (7.3)0.27%—AMD Management Console12/11/202417/6/2026
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaMedia (5.5)0.22%—AMD Ryzen AI Software12/11/202417/6/2026
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
AnalizadaAlta (7.3)0.24%—AMD Ryzen Master Utility FOR Overclocking Control12/11/202417/6/2026
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaAlta (7.3)0.24%—AMD Ryzen Master Monitoring Software Development KIT12/11/202417/6/2026
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaAlta (7.3)0.23%—AMD Cloud Manageability Service12/11/202417/6/2026
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaAlta (7.8)0.22%—AMD Management Plugin FOR Sccm12/11/202417/6/2026
Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AnalizadaAlta (7.8)0.26%—AMD Radeon SoftwareAMD Radeon Software FOR HIP12/11/202417/6/2026
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AnalizadaMedia (5.4)0.26%—Essamamdani Advanced Blocks PRO10/10/202417/6/2026
The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AnalizadaAlta (8.2)0.20%—Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+1628/8/202417/6/2026
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
AplazadaMedia (5.7)0.14%—AMD Secure ProcessorAI13/8/202417/6/2026
Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.
ModificadaMedia (5.5)0.15%—AMD Uprof13/8/202417/6/2026
Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.
AplazadaMedia (4.4)0.21%—AMD SEV FirmwareAI13/8/202417/6/2026
Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.
ModificadaAlta (7.8)0.16%—AMD Uprof13/8/202417/6/2026
Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
ModificadaAlta (7.8)0.18%—AMD Uprof13/8/202417/6/2026
A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
ModificadaMedia (5.5)0.13%—AMD Uprof13/8/202417/6/2026
Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.
AnalizadaMedia (5.8)0.16%—AMD Trusted Firmware-aTrustedfirmware Trusted Firmware-a13/8/202417/6/2026
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
AplazadaMedia (5)0.14%—AMD Power Management FirmwareAI13/8/202417/6/2026
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.
AnalizadaMedia (4.4)0.15%—AMD Radeon Software13/8/202417/6/2026
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
ModificadaCrítica (10)0.30%—AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+6113/8/202417/6/2026
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
AnalizadaMedia (6)0.19%—AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+6113/8/202417/6/2026
IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.