Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29232
Total
2268
Critical
8711
High
9096
Medium
CVE ID Severity Score Description Published
CVE-2026-7373 UNKNOWN Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup … May 15, 2026
CVE-2026-2652 HIGH 8.6 A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) … May 15, 2026
CVE-2026-0428 UNKNOWN Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGS to write invalid data to a remote Die, potentially … May 15, 2026
CVE-2026-0427 UNKNOWN Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources … May 15, 2026
CVE-2025-66664 UNKNOWN Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds … May 15, 2026
CVE-2025-66660 UNKNOWN Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in … May 15, 2026
CVE-2025-54517 UNKNOWN Out of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution. May 15, 2026
CVE-2025-54511 UNKNOWN Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient … May 15, 2026
CVE-2025-48516 UNKNOWN Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC … May 15, 2026
CVE-2025-48513 UNKNOWN Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of … May 15, 2026
CVE-2025-29944 UNKNOWN A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of … May 15, 2026
CVE-2025-29938 UNKNOWN An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial … May 15, 2026
CVE-2025-29937 UNKNOWN An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location … May 15, 2026
CVE-2025-29936 UNKNOWN Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or … May 15, 2026
CVE-2025-29935 UNKNOWN An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level … May 15, 2026
CVE-2025-0044 UNKNOWN An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially lead to a partial loss of confidentiality and … May 15, 2026
CVE-2025-0040 UNKNOWN Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical access to read or … May 15, 2026
CVE-2025-0028 UNKNOWN An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in … May 15, 2026
CVE-2024-36332 UNKNOWN Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to perform unauthorized access to specific victim … May 15, 2026
CVE-2024-21962 UNKNOWN Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and … May 15, 2026
CVE-2023-31317 UNKNOWN Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write … May 15, 2026
CVE-2023-31316 UNKNOWN Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability … May 15, 2026
CVE-2023-31309 UNKNOWN Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to … May 15, 2026
CVE-2022-23826 UNKNOWN A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly creating a race condition potentially leading to a … May 15, 2026
CVE-2021-26380 UNKNOWN A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside the intended range resulting in loss of … May 15, 2026