CVE-2024-38063
Last Modified: 10 Jul 2025Windows TCP/IP Remote Code Execution Vulnerability
CVE-2024-38084
Last Modified: 10 Jul 2025Microsoft OfficePlus Elevation of Privilege Vulnerability
CVE-2024-38213
Last Modified: 28 Oct 2025Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-38201
Last Modified: 10 Jul 2025Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2024-38199
Last Modified: 10 Jul 2025Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
CVE-2024-38198
Last Modified: 10 Jul 2025Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2024-38197
Last Modified: 10 Jul 2025Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-38196
Last Modified: 10 Jul 2025Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2024-38193
Last Modified: 28 Oct 2025Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2024-38191
Last Modified: 10 Jul 2025Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38184
Last Modified: 10 Jul 2025Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2024-38178
Last Modified: 28 Oct 2025Scripting Engine Memory Corruption Vulnerability
CVE-2024-38172
Last Modified: 10 Jul 2025Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-38161
Last Modified: 10 Jul 2025Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2024-38160
Last Modified: 10 Jul 2025Windows Network Virtualization Remote Code Execution Vulnerability
CVE-2024-38159
Last Modified: 10 Jul 2025Windows Network Virtualization Remote Code Execution Vulnerability
CVE-2024-38123
Last Modified: 10 Jul 2025Windows Bluetooth Driver Information Disclosure Vulnerability
CVE-2024-38108
Last Modified: 10 Jul 2025Azure Stack Hub Spoofing Vulnerability
CVE-2023-31366
Last Modified: 12 Dec 2024Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.
CVE-2023-31349
Last Modified: 12 Dec 2024Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2023-31348
Last Modified: 12 Dec 2024A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2023-31341
Last Modified: 26 Feb 2025Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.
CVE-2023-31339
Last Modified: 5 Jun 2026Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
CVE-2024-21981
Last Modified: 15 Apr 2026Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.
CVE-2023-31310
Last Modified: 15 Apr 2026Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.
CVE-2023-31307
Last Modified: 13 Dec 2024Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
CVE-2023-31304
Last Modified: 15 Apr 2026Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, potentially leading to a loss of availability.
CVE-2023-31305
Last Modified: 15 Apr 2026Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.
CVE-2023-20591
Last Modified: 13 Mar 2025Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
CVE-2023-20578
Last Modified: 18 Mar 2025A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
CVE-2023-20518
Last Modified: 15 Apr 2026Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
CVE-2023-20513
Last Modified: 15 Apr 2026An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.
CVE-2023-20512
Last Modified: 15 Apr 2026A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.
CVE-2023-20510
Last Modified: 12 Dec 2024An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.
CVE-2023-20509
Last Modified: 15 Apr 2026An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.
CVE-2022-23817
Last Modified: 15 May 2026Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
CVE-2022-23815
Last Modified: 18 Mar 2025Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
CVE-2021-46772
Last Modified: 15 Apr 2026Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure headers in SPI ROM causing an out of bounds memory read and write, potentially resulting in memory corruption or denial of service.
CVE-2021-46746
Last Modified: 15 Apr 2026Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.
CVE-2021-26387
Last Modified: 15 Apr 2026Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.
CVE-2021-26367
Last Modified: 12 Dec 2024A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.
CVE-2021-26344
Last Modified: 18 Mar 2025An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.
CVE-2024-6619
Last Modified: 15 Apr 2026In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.
CVE-2024-6618
Last Modified: 15 Apr 2026In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).
CVE-2024-7113
Last Modified: 15 Apr 2026If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.
CVE-2024-21757
Last Modified: 22 Aug 2024A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin passwords via the device configuration backup.
CVE-2022-27486
Last Modified: 22 Aug 2024A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 through 6.3.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 allows an authenticated attacker to execute shell code as `root` via `execute` CLI commands.
CVE-2022-45862
Last Modified: 22 Aug 2024An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use websessions after GUI logout, should they manage to acquire the required credentials.
CVE-2024-36505
Last Modified: 22 Aug 2024An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.
CVE-2023-26211
Last Modified: 22 Aug 2024An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
