ZeroHour

Vulnerabilities

292 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0466
+1 in the same advisory: …28237
Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in cras

Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.

NVD description · AI analysis pending
6.8<1%
  • amd uprof
CVE-2026-49121
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker.

NVD description · AI analysis pending
9.21% PoC
  • amd aiter
CVE-2024-36333
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code executi

A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.0<1%
  • amd radeon software
  • amd cleanup utility
CVE-2023-31324
+1 in the same advisory: …20548
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trus

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.

NVD description · AI analysis pending
7.1<1%
  • amd rocm
  • amd radeon software
  • amd radeon pro vii firmware
  • +1 more
CVE-2025-48510
+2 in the same advisory: …48511 …29933
Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.

Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.

NVD description · AI analysis pending
7.1
group max
<1%
  • amd uprof
CVE-2025-48502
Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.

NVD description · AI analysis pending
5.5<1%
  • amd uprof
CVE-2023-31358
+1 in the same advisory: …31359
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code exec

A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.8<1%
  • amd aim-t manageability api
CVE-2024-36340
A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file del

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

NVD description · AI analysis pending
6.6<1%
  • amd uprof
CVE-2024-21975
+2 in the same advisory: …21974 …21949
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.

NVD description · AI analysis pending
7.8
group max
<1%
  • amd ryzen ai software
CVE-2024-21958
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially result

Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.3<1%
  • amd provisioning console
CVE-2024-21957
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting

Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.3<1%
  • amd management console
CVE-2024-21946
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resul

Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.3<1%
  • amd ryzen master utility for overclocking control
CVE-2024-21945
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentiall

Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.3<1%
  • amd ryzen master monitoring software development kit
CVE-2024-21939
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalat

Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.3<1%
  • amd cloud manageability service
CVE-2024-21938
Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an a

Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.8<1%
  • amd management plugin for sccm
CVE-2024-21937
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitra

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.8<1%
  • amd radeon software
  • amd radeon software for hip
CVE-2024-9074
The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due t

The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

NVD description · AI analysis pending
5.4<1%
  • essamamdani advanced blocks pro
CVE-2023-31348
+3 in the same advisory: …31349 …31366 …31341
A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

NVD description · AI analysis pending
7.8
group max
<1%
  • amd uprof
CVE-2023-31339
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads,

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

NVD description · AI analysis pending
5.8<1%
  • amd trusted firmware-a
CVE-2021-26367
+2 in the same advisory: …20510 …31307
A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, pote

A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.

NVD description · AI analysis pending
6.0
group max
<1%
  • amd radeon software
  • amd ryzen 9 5980hx firmware
  • amd ryzen 3 3300u firmware
  • +1 more
CVE-2023-20591
+2 in the same advisory: …20578 …20584
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hype

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

NVD description · AI analysis pending
10.0
group max
<1%
  • amd epyc 8024pn firmware
  • amd epyc 8024p firmware
  • amd epyc 8124pn firmware
  • +1 more
CVE-2022-23815
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary c

Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.

NVD description · AI analysis pending
8.2<1%
  • amd athlon silver 3050u firmware
  • amd athlon gold 3150u firmware
  • amd ryzen 7 3780u firmware
  • +1 more
CVE-2021-26344
An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image,

An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

NVD description · AI analysis pending
8.2<1%
  • amd epyc 7203 firmware
  • amd epyc 7203p firmware
  • amd epyc 72f3 firmware
  • +1 more
CVE-2024-21978
+2 in the same advisory: …21980 …31355
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption

Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

NVD description · AI analysis pending
7.9
group max
<1%
  • amd epyc 7203 firmware
  • amd epyc 7203p firmware
  • amd epyc 72f3 firmware
  • +1 more
CVE-2023-31346
+1 in the same advisory: …31347
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

NVD description · AI analysis pending
6.0
group max
<1%
  • amd epyc 7773x firmware
  • amd epyc 7763 firmware
  • amd epyc 7713 firmware
  • +1 more
CVE-2023-20579
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resultin

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

NVD description · AI analysis pending
6.0<1%
  • amd ryzen 7 5700g firmware
  • amd ryzen 7 5700ge firmware
  • amd ryzen 5 5600g firmware
  • +1 more
CVE-2021-46757
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address spac

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.

NVD description · AI analysis pending
7.8<1%
  • amd ryzen embedded 5950e firmware
  • amd ryzen embedded 5900e firmware
  • amd ryzen embedded 5800e firmware
  • +1 more
CVE-2023-20570
Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.

Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.

NVD description · AI analysis pending
3.3<1%
  • amd alveo u50 firmware
  • amd alveo u200 firmware
  • amd alveo u250 firmware
  • +1 more
CVE-2023-4969
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on var

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

NVD description · AI analysis pending
6.51% PoC
  • khronos opencl
  • khronos vulkan
  • khronos ddk
  • +1 more
CVE-2023-20573
A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.

A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.

NVD description · AI analysis pending
3.2<1%
  • amd epyc 7763 firmware
  • amd epyc 7713p firmware
  • amd epyc 7713 firmware
  • +1 more
CVE-2023-31320
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.

Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.

NVD description · AI analysis pending
7.51%
  • amd radeon software
  • amd radeon rx vega 56 firmware
  • amd radeon rx vega 64 firmware
  • +1 more
CVE-2023-20596
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code

Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.

NVD description · AI analysis pending
9.81%
  • amd ryzen 7 5700g firmware
  • amd ryzen 7 5700ge firmware
  • amd ryzen 5 5600g firmware
  • +1 more
CVE-2023-20592
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behav

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

NVD description · AI analysis pending
6.51%
  • amd epyc 7001 firmware
  • amd epyc 7251 firmware
  • amd epyc 7261 firmware
  • +1 more