Vulnerabilities in nvidia
888 resultsVexday analysis
A NVIDIA apresenta 49 vulnerabilidades catalogadas, das quais 4 são críticas, mas nenhuma está sob ataque ativo no momento. A ausência de publicações nos últimos 90 dias indica um panorama estável, embora a fraqueza dominante seja a desreferência de ponteiro nulo (CWE-476), típica de falhas de validação que podem causar negação de serviço. O risco atual é moderado e não apresenta pressão imediata de exploração em campo.
CVE-2025-23258HIGHNVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to EPSS 0.2%CVE-2026-65127MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information dEPSS 0.2%CVE-2025-23257HIGHNVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privEPSS 0.2%CVE-2026-24263HIGHNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer derefereEPSS 0.2%CVE-2022-42285MEDIUMDGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, EPSS 0.2%CVE-2025-33205HIGHNVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an unEPSS 0.2%CVE-2025-23355MEDIUMNVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A EPSS 0.2%CVE-2025-23337MEDIUMNVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with adEPSS 0.2%CVE-2025-23272MEDIUMNVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. EPSS 0.2%CVE-2026-24262HIGHNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write.EPSS 0.2%CVE-2026-24194HIGHNVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handliEPSS 0.2%CVE-2024-0098MEDIUMCVEEPSS 0.2%CVE-2026-24234MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker couldEPSS 0.2%CVE-2023-31034MEDIUMCVEEPSS 0.2%CVE-2026-65087MEDIUMNVIDIA NemoClaw contains a vulnerability where an attacker could cause
insufficiently protected credentials . A successful exploit of this vEPSS 0.2%CVE-2025-33194MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successEPSS 0.1%CVE-2024-53881MEDIUMNVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm on the host, which EPSS 0.1%CVE-2024-0094MEDIUMCVEEPSS 0.1%CVE-2024-0086MEDIUMCVEEPSS 0.1%CVE-2023-0207HIGHNVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged cEPSS 0.1%