Vulnerabilities in nvidia

888 results
Vexday analysis

A NVIDIA apresenta 49 vulnerabilidades catalogadas, das quais 4 são críticas, mas nenhuma está sob ataque ativo no momento. A ausência de publicações nos últimos 90 dias indica um panorama estável, embora a fraqueza dominante seja a desreferência de ponteiro nulo (CWE-476), típica de falhas de validação que podem causar negação de serviço. O risco atual é moderado e não apresenta pressão imediata de exploração em campo.

CVE-2019-5695—NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provEPSS 0.9%CVE-2024-0145MEDIUMNVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crEPSS 0.9%CVE-2021-1073HIGHNVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a broEPSS 0.9%CVE-2026-24254CRITICALNVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. AEPSS 0.9%CVE-2023-25528HIGHNVIDIA DGX H100 baseboard management controller (BMC) contains a vulnerability in a web server plugin, where an unauthenticated attacker mayEPSS 0.9%CVE-2024-0138CRITICALNVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerabEPSS 0.9%CVE-2025-33185MEDIUMNVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure.  A successful exploit of thEPSS 0.9%CVE-2023-25507HIGHNVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbiEPSS 0.9%CVE-2026-65083CRITICALNVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disEPSS 0.9%CVE-2023-31036HIGHCVEEPSS 0.9%CVE-2022-42273HIGHNVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.8%CVE-2025-23267HIGHNVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link followiEPSS 0.8%CVE-2023-25530HIGHNVIDIA DGX H100 BMC contains a vulnerability in the KVM service, where an attacker may cause improper input validation. A successful exploitEPSS 0.8%CVE-2026-47612HIGHNVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathnamEPSS 0.8%CVE-2026-24270CRITICALNVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability EPSS 0.8%CVE-2025-33224CRITICALNVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploiEPSS 0.8%CVE-2026-65093CRITICALNVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerabiliEPSS 0.8%CVE-2025-33180HIGHNVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A EPSS 0.8%CVE-2025-23334MEDIUMNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofEPSS 0.8%CVE-2023-25533HIGHNVIDIA DGX H100 BMC contains a vulnerability in the web UI, where an attacker may cause improper input validation. A successful exploit of tEPSS 0.8%