Vendor
Amd vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 70 vulnerabilities in Amd: 0 in the last 7 days and 11 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2023-20577, was published on 2 September 2026. 6 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 0
- Exploited in the wild
- 0
About Amd
Advanced Micro Devices, Inc. is an American fabless semiconductor company that develops computer processors and related technologies.
Amd technologies
Latest Amd vulnerabilities
- CVE-2023-20577: AMD firmware heap overflow in SMM modulehighCVSS 7.4EPSS 0.2%
- CVE-2023-20576: AMD AGESA insufficient verification of data authenticity in SPI ROMhighCVSS 7.7EPSS 0.1%
- CVE-2023-31308: AMD System Management Unit out-of-bounds memory read in command handlerslowCVSS 3.3EPSS 0.1%
- CVE-2023-20511: AMD kernel mode driver double free in pointer releasemediumCVSS 6.4EPSS 0.2%
- CVE-2026-0465: AMD Ryzen Master Utility Driver use-after-free in kernel memory accessinfoEPSS 0.1%
- CVE-2025-54512: AMD Ryzen Master DLL hijacking privilege escalationinfoEPSS 0.2%
- CVE-2025-8087: AMD Power Design Manager DLL hijacking in uninstallerinfoEPSS 0.2%
- CVE-2025-61970: AMD Vitis Unified weak installation permissionsinfoEPSS 0.1%
- CVE-2025-48506: AMD Vitis Unified DLL injection via uncontrolled search pathinfoEPSS 0.2%
- CVE-2025-48505: AMD Vitis Unified weak permissions privilege escalationinfoEPSS 0.1%
- CVE-2025-0041: AMD Vitis Embedded uncontrolled search path privilege escalationinfoEPSS 0.2%
- CVE-2023-20572: AMD Secure Processor timing discrepancy in HMAC verificationinfoCVSS 5.6
- CVE-2023-20540: AMD Secure Processor timing discrepancy in HMAC validationinfoCVSS 1.8
- CVE-2026-40677: AMD Optional Tools man-in-the-middle vulnerabilityinfoCVSS 7.7
- CVE-2024-21944: AMD BIOS improper input validation in DIMM SPD metadatamediumCVSS 5.3
- CVE-2026-28237: AMD uProf unrestricted resource allocationinfoCVSS 6.8
- CVE-2026-0466: AMD uProf improper access control in kernel-shared memoryinfoCVSS 6.8
- CVE-2025-54509: AMD IOMMU improper access control in register interfaceinfoCVSS 5.1
- CVE-2021-46747: AMD Secure Processor privilege escalation via insufficient SMN access controlinfoCVSS 7.1
- CVE-2026-49121: AMD AITER remote code execution in MessageQueue.recvhighCVSS 8.1
- CVE-2024-36343: AMD Processor out of bounds read/write in SMM communications bufferinfoCVSS 6.7
- CVE-2026-0481: AMD Device Metrics Exporter unrestricted IP address bindinginfoCVSS 9.2
- CVE-2025-54518: AMD Zen 2 Processors privilege escalation via CPU Opcode Cache corruptionhighCVSS 7EPSS 0.3%
- CVE-2025-52532: AMD MxGPU-Virtualization driver race condition in ioctl handlerinfoCVSS 2
- CVE-2024-36334: AMD Radeon RGB tool improper signature verificationinfoCVSS 7
Most severe Amd vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-49121: AMD AITER remote code execution in MessageQueue.recvhighCVSS 8.1
- CVE-2024-36333: AMD Cleanup Utility DLL hijacking privilege escalationhighCVSS 7.8EPSS 0.0%
- CVE-2023-20576: AMD AGESA insufficient verification of data authenticity in SPI ROMhighCVSS 7.7EPSS 0.1%
- CVE-2025-54502: AMD APCB SMM driver privilege escalation in multiple processorshighCVSS 7.5EPSS 0.1%
- CVE-2023-20577: AMD firmware heap overflow in SMM modulehighCVSS 7.4EPSS 0.2%
- CVE-2025-54518: AMD Zen 2 Processors privilege escalation via CPU Opcode Cache corruptionhighCVSS 7EPSS 0.3%
- CVE-2023-20511: AMD kernel mode driver double free in pointer releasemediumCVSS 6.4EPSS 0.2%
- CVE-2024-21944: AMD BIOS improper input validation in DIMM SPD metadatamediumCVSS 5.3
- CVE-2023-31308: AMD System Management Unit out-of-bounds memory read in command handlerslowCVSS 3.3EPSS 0.1%
- CVE-2026-0481: AMD Device Metrics Exporter unrestricted IP address bindinginfoCVSS 9.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 7 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 4 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/amd.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Amd vulnerabilities", https://junglewise.ai/threats/vendors/amd, 26 September 2026.