Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26848
Total
1978
Critical
8065
High
8299
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-48513 | UNKNOWN | — | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of … | May 15, 2026 |
| CVE-2025-29944 | UNKNOWN | — | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of … | May 15, 2026 |
| CVE-2025-29938 | UNKNOWN | — | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial … | May 15, 2026 |
| CVE-2025-29937 | UNKNOWN | — | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location … | May 15, 2026 |
| CVE-2025-29936 | UNKNOWN | — | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or … | May 15, 2026 |
| CVE-2025-29935 | UNKNOWN | — | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level … | May 15, 2026 |
| CVE-2025-0044 | UNKNOWN | — | An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially lead to a partial loss of confidentiality and … | May 15, 2026 |
| CVE-2025-0040 | UNKNOWN | — | Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical access to read or … | May 15, 2026 |
| CVE-2025-0028 | UNKNOWN | — | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in … | May 15, 2026 |
| CVE-2024-36332 | UNKNOWN | — | Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to perform unauthorized access to specific victim … | May 15, 2026 |
| CVE-2024-21962 | UNKNOWN | — | Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and … | May 15, 2026 |
| CVE-2023-31317 | UNKNOWN | — | Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write … | May 15, 2026 |
| CVE-2023-31316 | UNKNOWN | — | Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability … | May 15, 2026 |
| CVE-2023-31309 | UNKNOWN | — | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to … | May 15, 2026 |
| CVE-2022-23826 | UNKNOWN | — | A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly creating a race condition potentially leading to a … | May 15, 2026 |
| CVE-2021-26380 | UNKNOWN | — | A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside the intended range resulting in loss of … | May 15, 2026 |
| CVE-2026-8612 | MEDIUM | 5.3 | WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit … | May 15, 2026 |
| CVE-2026-0438 | UNKNOWN | — | A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction … | May 15, 2026 |
| CVE-2026-0432 | UNKNOWN | — | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | May 15, 2026 |
| CVE-2025-52540 | UNKNOWN | — | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege … | May 15, 2026 |
| CVE-2025-48521 | UNKNOWN | — | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in … | May 15, 2026 |
| CVE-2025-48520 | UNKNOWN | — | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information … | May 15, 2026 |
| CVE-2025-48519 | UNKNOWN | — | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting … | May 15, 2026 |
| CVE-2025-48512 | UNKNOWN | — | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary … | May 15, 2026 |
| CVE-2025-0045 | UNKNOWN | — | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in … | May 15, 2026 |