Total
398853 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-48518 | 2026-06-17 | N/A | N/A | ||
| Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service. | |||||
| CVE-2025-48517 | 2026-06-17 | N/A | N/A | ||
| Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of confidentiality. | |||||
| CVE-2025-48516 | 2026-06-17 | N/A | N/A | ||
| Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module. | |||||
| CVE-2025-48515 | 2026-06-17 | N/A | N/A | ||
| Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution. | |||||
| CVE-2025-48514 | 2026-06-17 | N/A | N/A | ||
| Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality. | |||||
| CVE-2025-48513 | 2026-06-17 | N/A | N/A | ||
| Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability. | |||||
| CVE-2025-48512 | 2026-06-17 | N/A | N/A | ||
| Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | |||||
| CVE-2025-48511 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service. | |||||
| CVE-2025-48510 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 7.1 HIGH |
| Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability. | |||||
| CVE-2025-48509 | 2026-06-17 | N/A | N/A | ||
| Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause misidentification of I/O memory, potentially resulting in a loss of guest memory integrity | |||||
| CVE-2025-48508 | 2026-06-17 | N/A | 6.0 MEDIUM | ||
| Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or reset resulting in denial of service. | |||||
| CVE-2025-48507 | 2026-06-17 | N/A | N/A | ||
| The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC. | |||||
| CVE-2025-48503 | 2026-06-17 | N/A | 7.8 HIGH | ||
| A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2025-48502 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service. | |||||
| CVE-2025-48501 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running. | |||||
| CVE-2025-48500 | 2 Apple, F5 | 3 Macos, Big-ip Access Policy Manager, Big-ip Access Policy Manager Client | 2026-06-17 | N/A | 7.3 HIGH |
| A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |||||
| CVE-2025-48499 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a denial-of-service (DoS) condition on an affected MFP. Resetting the MFP is required to recover from the denial-of-service (DoS) condition. | |||||
| CVE-2025-48498 | 1 Bloomberg | 1 Comdb2 | 2026-06-17 | N/A | 7.5 HIGH |
| A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability. | |||||
| CVE-2025-48497 | 1 Irohasoft | 1 Iroha Board | 2026-06-17 | N/A | 4.3 MEDIUM |
| Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered. | |||||
| CVE-2025-48496 | 2026-06-17 | N/A | 5.1 MEDIUM | ||
| Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. | |||||
