Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.14% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity. | |
| Aplazada | Media (4.6) | 0.14% | — | AMD SEV FirmwareAIAMD Sev-esAIAMD Sev-snpAI | 10/2/2026 | 17/6/2026 | Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of confidentiality. | |
| Aplazada | Media (4) | 0.14% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality. | |
| Aplazada | Media (4.5) | 0.15% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory. | |
| Aplazada | Media (4.6) | 0.12% | — | AMD SEV FirmwareAI | 10/2/2026 | 17/6/2026 | A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity. | |
| Aplazada | Media (6) | 0.18% | — | AMD SEV FirmwareAI | 11/2/2025 | 17/6/2026 | A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data. | |
| Aplazada | Media (4.4) | 0.21% | — | AMD SEV FirmwareAI | 13/8/2024 | 17/6/2026 | Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity. |