Amd
17 CVEs tracked since 2023. Since Jan 2023, none of them reached CISA KEV.
Amd CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-01 | 17 | 0 |
Products
The products that kept showing up in Amd's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Amd.
- CVE-2023-20577A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.7.4
- CVE-2023-20576Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.7.7
- CVE-2023-31308A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.3.3
- CVE-2023-20511Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.6.4
- CVE-2025-54512A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.—
- CVE-2026-0465A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability—
- CVE-2025-0046Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.—
- CVE-2025-8087A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code ex...—
- CVE-2025-48505Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code exec...—
- CVE-2025-48506Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.—
- CVE-2025-61970Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.—
- CVE-2025-0041Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.—
- CVE-2026-43606Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attack...—
- CVE-2023-20572An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary messag...—
- CVE-2023-20540An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary message input, potenti...5.2
The record
- Peak rank
- #46 in Jan 2023
- Busiest month shown
- Jan 2023, 17 CVEs
- Months with a KEV entry
- 0 since Jan 2023
- Monthly snapshots
- 1 since 2023