CVE Vulnerability Database

Search and browse 397,953 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-29937MEDIUM5.8An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an...
CVE-2025-29936HIGH8.4Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary ...
CVE-2025-29935HIGH8.4An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary c...
CVE-2025-0044MEDIUM4.8An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially l...
CVE-2025-0040MEDIUM5.3Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow a...
CVE-2025-0028HIGH8.3An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify ...
CVE-2024-36332MEDIUM6.8Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to...
CVE-2024-21962HIGH8.6Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potent...
CVE-2023-31317HIGH8.8Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an...
CVE-2023-31316HIGH7.1Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure P...
CVE-2023-31309MEDIUM6.8Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload...
CVE-2022-23826LOW1.8A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly cre...
CVE-2021-26380LOW1.8A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside t...
CVE-2026-8612MEDIUM5.3WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cac...
CVE-2026-0438MEDIUM5.4A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly pri...
CVE-2026-0432HIGH8.5Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev...
CVE-2025-52540HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local a...
CVE-2025-48521MEDIUM6.9Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-Aft...
CVE-2025-48520MEDIUM6.9An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a...
CVE-2025-48519HIGH8.5An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local a...
CVE-2025-48512HIGH7Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) c...
CVE-2025-0045MEDIUM6.9Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer ove...
CVE-2024-36345MEDIUM4.6Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attack...
CVE-2026-6811HIGH7.5Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO...
CVE-2026-45248MEDIUM6.9Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e...