Vulnerabilities in NVIDIA

888 results
Vexday analysis

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2025-33176MEDIUMNVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adEPSS 0.1%CVE-2025-23256HIGHNVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorizatiEPSS 0.1%CVE-2023-25521HIGH NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging EPSS 0.1%CVE-2025-23297HIGHNVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unpriEPSS 0.1%CVE-2025-23245MEDIUMNVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to accEPSS 0.1%CVE-2025-23300MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocaEPSS 0.1%CVE-2025-33195MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A succeEPSS 0.1%CVE-2025-23290LOWNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influencedEPSS 0.1%CVE-2023-31014MEDIUMNVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device canEPSS 0.1%CVE-2023-31020MEDIUMCVEEPSS 0.1%CVE-2026-24201MEDIUMNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successfulEPSS 0.1%CVE-2025-33192MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read. A successful exploEPSS 0.1%CVE-2025-23332MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deferEPSS 0.1%CVE-2026-24181HIGHNVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of thisEPSS 0.1%CVE-2023-0192MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can leaEPSS 0.1%CVE-2025-33199LOWNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successfuEPSS 0.1%CVE-2025-33196MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploiEPSS 0.1%CVE-2025-33200LOWNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploiEPSS 0.1%CVE-2025-23269MEDIUMNVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive information due to a shared EPSS 0.1%CVE-2026-24191HIGHNVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful expEPSS 0.1%