Vulnerabilidades en NVIDIA

742 resultados
Análisis Vexday

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2025-33189HIGHNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit EPSS 0.2%CVE-2025-33231MEDIUMNVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an unconEPSS 0.2%CVE-2023-25519HIGH NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrecEPSS 0.2%CVE-2026-24198MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memoryEPSS 0.2%CVE-2026-24180HIGHNVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of thisEPSS 0.2%CVE-2022-42285MEDIUMDGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, EPSS 0.2%CVE-2025-23281HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race conditioEPSS 0.2%CVE-2026-24194HIGHNVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handliEPSS 0.2%CVE-2025-33187CRITICALNVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areasEPSS 0.2%CVE-2025-23261MEDIUMNVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentEPSS 0.2%CVE-2025-33212HIGHNVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a useEPSS 0.2%CVE-2024-0098MEDIUMCVEEPSS 0.2%CVE-2023-31034MEDIUMCVEEPSS 0.2%CVE-2024-0086MEDIUMCVEEPSS 0.1%CVE-2024-0094MEDIUMCVEEPSS 0.1%CVE-2025-23347HIGHNVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulneEPSS 0.1%CVE-2023-0207HIGHNVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged cEPSS 0.1%CVE-2025-33176MEDIUMNVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adEPSS 0.1%CVE-2025-23285MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful eEPSS 0.1%CVE-2024-53881MEDIUMNVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm on the host, which EPSS 0.1%