CVE Vulnerability Database
Search and browse 397,953 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29937 | MEDIUM | 5.8 | 0.1% | May 15, 2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an... |
| CVE-2025-29936 | HIGH | 8.4 | 0.1% | May 15, 2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ... |
| CVE-2025-29935 | HIGH | 8.4 | 0.1% | May 15, 2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c... |
| CVE-2025-0044 | MEDIUM | 4.8 | 0.1% | May 15, 2026 | An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l... |
| CVE-2025-0040 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a... |
| CVE-2025-0028 | HIGH | 8.3 | 0.1% | May 15, 2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ... |
| CVE-2024-36332 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to... |
| CVE-2024-21962 | HIGH | 8.6 | 0.1% | May 15, 2026 | Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent... |
| CVE-2023-31317 | HIGH | 8.8 | 0.1% | May 15, 2026 | Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an... |
| CVE-2023-31316 | HIGH | 7.1 | 0.1% | May 15, 2026 | Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure P... |
| CVE-2023-31309 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload... |
| CVE-2022-23826 | LOW | 1.8 | 0.1% | May 15, 2026 | A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly cre... |
| CVE-2021-26380 | LOW | 1.8 | 0.1% | May 15, 2026 | A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside t... |
| CVE-2026-8612 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cac... |
| CVE-2026-0438 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly pri... |
| CVE-2026-0432 | HIGH | 8.5 | 0.1% | May 15, 2026 | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev... |
| CVE-2025-52540 | HIGH | 8.5 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a... |
| CVE-2025-48521 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft... |
| CVE-2025-48520 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-48519 | HIGH | 8.5 | 0.1% | May 15, 2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a... |
| CVE-2025-48512 | HIGH | 7 | 0.1% | May 15, 2026 | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c... |
| CVE-2025-0045 | MEDIUM | 6.9 | 0.1% | May 15, 2026 | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove... |
| CVE-2024-36345 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack... |
| CVE-2026-6811 | HIGH | 7.5 | 0.4% | May 14, 2026 | Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO... |
| CVE-2026-45248 | MEDIUM | 6.9 | 0.4% | May 14, 2026 | Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e... |
