Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.12%—AMD Epyc 8024pn FirmwareAMD Epyc 8024p FirmwareAMD Epyc 8124pn FirmwareAMD Epyc 8124p Firmware+10113/8/202417/6/2026
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
AnalizadaMedia (6)0.14%—AMD Radeon Software13/8/202417/6/2026
An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.
AplazadaAlta (7.3)0.18%—AMD Secure ProcessorAIAMD Secure OSAI13/8/202417/6/2026
Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
ModificadaAlta (8.2)0.16%—AMD Athlon Silver 3050u FirmwareAMD Athlon Gold 3150u FirmwareAMD Ryzen 7 3780u FirmwareAMD Ryzen 7 3750h Firmware+1213/8/202417/6/2026
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
AplazadaMedia (5.2)0.15%—AMD ASP Secure OSAI13/8/202417/6/2026
Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.
AplazadaBaja (3.9)0.15%—AMD ASP KernelAI13/8/202417/6/2026
Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.
AnalizadaMedia (6)0.16%—AMD Radeon SoftwareAMD Ryzen 9 5980hx FirmwareAMD Ryzen 3 3300u FirmwareAMD Ryzen 3 3350u Firmware+3213/8/202417/6/2026
A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.
ModificadaAlta (8.2)0.16%—AMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+6513/8/202417/6/2026
An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.
AnalizadaAlta (7.9)0.45%💥 PoCAMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+825/8/202417/6/2026
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
AnalizadaAlta (7.9)0.49%💥 PoCAMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+825/8/202417/6/2026
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
AnalizadaMedia (6)0.44%💥 PoCAMD Epyc 7203 FirmwareAMD Epyc 7203p FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7303 Firmware+825/8/202417/6/2026
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
AplazadaAlta (8.2)0.20%—AMD SPI Protection FeaturesAI18/6/202417/6/2026
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
ModificadaAlta (8.2)0.18%—Dell Alienware Area 51M R2 FirmwareDell Alienware Aurora R11 FirmwareDell Alienware Aurora R12 FirmwareDell Alienware Aurora R13 Firmware+1813/6/202417/6/2026
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
ModificadaAlta (8.2)0.18%—Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+1913/6/202417/6/2026
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
ModificadaAlta (8.2)0.18%—Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+1913/6/202417/6/2026
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
ModificadaMedia (6)0.15%—Dell XPS 8960 FirmwareDell XPS 8950 FirmwareDell Inspiron 3502 FirmwareDell Inspiron 15 3521 Firmware+1913/6/202417/6/2026
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
ModificadaAlta (7.6)0.17%—Dell Vostro 5625 FirmwareDell Vostro 5515 FirmwareDell Vostro 5415 FirmwareDell Vostro 3405 Firmware+367/6/202417/6/2026
Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.
AplazadaMedia (5.3)0.19%—AMD Radeon User Mode DriverAI23/4/202417/6/2026
An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.
AplazadaMedia (5.3)0.19%—AMD Radeon User Mode DriverAI23/4/202417/6/2026
An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.
ModificadaMedia (4.9)0.46%—AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713 FirmwareAMD Epyc 7713p Firmware+5813/2/202417/6/2026
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
ModificadaMedia (6)0.31%💥 PoCAMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713 FirmwareAMD Epyc 7713p Firmware+5813/2/202417/6/2026
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
ModificadaMedia (6)0.16%—AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600gt Firmware+12513/2/20242/9/2026
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
ModificadaAlta (7.8)0.18%—AMD Ryzen Embedded 5950e FirmwareAMD Ryzen Embedded 5900e FirmwareAMD Ryzen Embedded 5800e FirmwareAMD Ryzen Embedded 5600e Firmware+613/2/202417/6/2026
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.
ModificadaBaja (3.3)0.10%—AMD Alveo U50 FirmwareAMD Alveo U200 FirmwareAMD Alveo U250 FirmwareAMD Alveo U280 Firmware+4313/2/202417/6/2026
Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.
ModificadaMedia (6.5)1.2%—Khronos OpenclKhronos VulkanImaginationtech DDKAMD Instinct Mi300x Firmware+12816/1/202417/6/2026
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.