Vulnerabilities in nvidia
888 resultsVexday analysis
A NVIDIA apresenta 49 vulnerabilidades catalogadas, das quais 4 são críticas, mas nenhuma está sob ataque ativo no momento. A ausência de publicações nos últimos 90 dias indica um panorama estável, embora a fraqueza dominante seja a desreferência de ponteiro nulo (CWE-476), típica de falhas de validação que podem causar negação de serviço. O risco atual é moderado e não apresenta pressão imediata de exploração em campo.
CVE-2025-23275MEDIUMNVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds writEPSS 0.1%CVE-2025-23286MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit oEPSS 0.1%CVE-2025-33198LOWNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploiEPSS 0.1%CVE-2026-24225MEDIUMNVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A suEPSS 0.1%CVE-2026-65129MEDIUMNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%CVE-2025-23288LOWNVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may cause an exposure of sensitive system information withEPSS 0.1%CVE-2025-33237MEDIUMNVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful eEPSS 0.1%CVE-2025-23274MEDIUMNVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted inpuEPSS 0.1%CVE-2026-65118HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successEPSS 0.1%CVE-2025-23289MEDIUMNVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive informatioEPSS 0.1%CVE-2026-24183HIGHNVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege manaEPSS 0.1%CVE-2025-23273LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a divide by zero error bEPSS 0.1%CVE-2026-24231MEDIUMNVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-sideEPSS 0.1%CVE-2024-0139MEDIUMNVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A successful exploit of tEPSS 0.1%CVE-2025-23291LOWNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized actioEPSS 0.1%CVE-2026-24166MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic kEPSS 0.1%CVE-2025-33235HIGHNVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A suEPSS 0.1%CVE-2026-24182MEDIUMNVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit ofEPSS 0.1%CVE-2022-42284MEDIUMNVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.EPSS 0.1%CVE-2026-24153MEDIUMNVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerEPSS 0.1%