Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.11% | — | AMD Secure Processor FirmwareAIAMD ZEN 5AI | 16/4/2026 | 17/6/2026 | A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity. | |
| Modificada | Alta (8.2) | 0.16% | — | AMD Athlon Silver 3050u FirmwareAMD Athlon Gold 3150u FirmwareAMD Ryzen 7 3780u FirmwareAMD Ryzen 7 3750h Firmware+12 | 13/8/2024 | 17/6/2026 | Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution. | |
| Analizada | Media (6) | 0.16% | — | AMD Radeon SoftwareAMD Ryzen 9 5980hx FirmwareAMD Ryzen 3 3300u FirmwareAMD Ryzen 3 3350u Firmware+32 | 13/8/2024 | 17/6/2026 | A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability. | |
| Modificada | Media (6) | 0.16% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600gt Firmware+125 | 13/2/2024 | 2/9/2026 | Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability. | |
| Modificada | Media (6.5) | 1.2% | — | Khronos OpenclKhronos VulkanImaginationtech DDKAMD Instinct Mi300x Firmware+128 | 16/1/2024 | 17/6/2026 | A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures. | |
| Modificada | Crítica (9.8) | 1.0% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600ge Firmware+60 | 14/11/2023 | 17/6/2026 | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution. | |
| Modificada | Alta (8.1) | 0.45% | — | AMD Ryzen 3 5100 FirmwareAMD Ryzen 3 5300g FirmwareAMD Ryzen 3 5300ge FirmwareAMD Ryzen 5 5500 Firmware+67 | 14/11/2023 | 17/6/2026 | A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation. | |
| Modificada | Alta (7.8) | 0.21% | — | AMD Ryzen 3 5100 FirmwareAMD Ryzen 3 5300g FirmwareAMD Ryzen 3 5300ge FirmwareAMD Ryzen 5 5500 Firmware+67 | 14/11/2023 | 17/6/2026 | Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | AMD Ryzen 3 5100 FirmwareAMD Ryzen 3 5300g FirmwareAMD Ryzen 3 5300ge FirmwareAMD Ryzen 5 5500 Firmware+67 | 14/11/2023 | 17/6/2026 | Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.50% | — | AMD Epyc 7232p FirmwareAMD Epyc 7252 FirmwareAMD Epyc 7262 FirmwareAMD Epyc 7272 Firmware+81 | 14/11/2023 | 17/6/2026 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service. | |
| Modificada | Media (5.7) | 0.26% | — | AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+89 | 14/11/2023 | 17/6/2026 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. | |
| Modificada | Crítica (9.8) | 0.99% | — | AMD Ryzen 9 3900 FirmwareAMD Ryzen 9 3900x FirmwareAMD Ryzen 9 3900xt FirmwareAMD Ryzen 9 3950x Firmware+104 | 14/11/2023 | 17/6/2026 | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 0.70% | — | AMD Ryzen 9 3900 FirmwareAMD Ryzen 9 3900x FirmwareAMD Ryzen 9 3900xt FirmwareAMD Ryzen 9 3950x Firmware+101 | 14/11/2023 | 17/6/2026 | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution. | |
| Modificada | Alta (7.5) | 0.51% | — | AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+133 | 14/11/2023 | 17/6/2026 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service. | |
| Modificada | Media (6.1) | 0.33% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600ge Firmware+57 | 14/11/2023 | 17/6/2026 | Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity. | |
| Modificada | Media (5.3) | 1.7% | — | Canonical Ubuntu LinuxAMD Ryzen 7 4800uIntel Core I7-10510uIntel Core I7-12700k+12 | 27/9/2023 | 17/6/2026 | PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text… | |
| Modificada | Media (5.5) | 0.18% | — | AMD Ryzen 3 3100 FirmwareAMD Ryzen 3 3200g FirmwareAMD Ryzen 3 3200ge FirmwareAMD Ryzen 3 3200u Firmware+97 | 20/9/2023 | 17/6/2026 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. | |
| Modificada | Media (4.4) | 0.19% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+121 | 20/9/2023 | 17/6/2026 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. | |
| Modificada | Media (6.8) | 0.58% | — | AMD Ryzen 5 PRO 3400g FirmwareAMD Ryzen 5 3400g FirmwareAMD Ryzen 5 PRO 3400ge FirmwareAMD Ryzen 5 PRO 3350g Firmware+118 | 8/8/2023 | 17/6/2026 | An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. | |
| Modificada | Media (5.5) | 11% | — | Debian LinuxAMD Epyc 7351p FirmwareAMD Epyc 7401p FirmwareAMD Epyc 7551p Firmware+43 | 8/8/2023 | 17/6/2026 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | |
| Modificada | Media (4.7) | 7.3% | — | Fedoraproject FedoraDebian LinuxAMD Ryzen 9 5950x FirmwareAMD Ryzen 9 5900x Firmware+151 | 8/8/2023 | 17/6/2026 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | |
| Modificada | Alta (7.8) | 0.32% | — | AMD Ryzen 3 3300 FirmwareAMD Ryzen 3 3300x FirmwareAMD Ryzen 5 3600 FirmwareAMD Ryzen 5 3600x Firmware+115 | 8/8/2023 | 17/6/2026 | Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM. | |
| Modificada | Media (5.5) | 5.2% | — | XENDebian LinuxAMD Ryzen 3 3100 FirmwareAMD Ryzen 3 3300x Firmware+67 | 24/7/2023 | 17/6/2026 | An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. | |
| Modificada | Media (5.9) | 0.40% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+51 | 9/5/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service. |