Vulnerabilidades en NVIDIA

888 resultados
Análisis Vexday

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2025-23318HIGHNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofEPSS 0.7%CVE-2025-23316CRITICALNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote EPSS 0.7%CVE-2023-31009HIGHNVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploiEPSS 0.7%CVE-2026-65090HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A suEPSS 0.7%CVE-2026-65089HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injectioEPSS 0.7%CVE-2026-65096HIGHNVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. EPSS 0.7%CVE-2026-65099HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A succEPSS 0.7%CVE-2023-31010MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vuEPSS 0.7%CVE-2025-33223CRITICALNVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploiEPSS 0.7%CVE-2025-23251HIGHNVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. EPSS 0.7%CVE-2024-0100MEDIUMCVEEPSS 0.7%CVE-2025-23249HIGHNVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A succEPSS 0.7%CVE-2025-33211HIGHNVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. AEPSS 0.7%CVE-2024-0143MEDIUMNVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause an out-of-bounds write issue by means of a specially crafted EPSS 0.7%CVE-2024-0136HIGHNVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted codeEPSS 0.7%CVE-2026-65098HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. EPSS 0.7%CVE-2026-24266MEDIUMNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit oEPSS 0.7%CVE-2025-33210CRITICALNVIDIA Isaac Lab contains a deserialization vulnerability. A successful exploit of this vulnerability might lead to code execution.EPSS 0.7%CVE-2025-33214HIGHNVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successfuEPSS 0.7%CVE-2025-33213HIGHNVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issueEPSS 0.7%