Vulnerabilities in NVIDIA

742 results
Vexday analysis

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2025-23322HIGHNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a streaEPSS 0.5%CVE-2025-23331HIGHNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive siEPSS 0.5%CVE-2026-24173HIGHNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the sEPSS 0.5%CVE-2026-24174HIGHNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the sEPSS 0.5%CVE-2023-0203MEDIUMNVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficEPSS 0.5%CVE-2023-0205MEDIUMNVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficEPSS 0.5%CVE-2023-25529HIGHNVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of EPSS 0.5%CVE-2019-5676NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system EPSS 0.5%CVE-2025-33179HIGHNVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized EPSS 0.5%CVE-2023-25534MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vuEPSS 0.5%CVE-2025-23323HIGHNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leEPSS 0.5%CVE-2021-39158HIGHDependency injection in NVCaffeEPSS 0.5%CVE-2021-1074HIGHNVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be ableEPSS 0.5%CVE-2024-0141MEDIUMNVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to writeEPSS 0.5%CVE-2023-31025MEDIUMCVEEPSS 0.5%CVE-2022-42282MEDIUMNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information EPSS 0.5%CVE-2026-24147MEDIUMNVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disclosure by uploading EPSS 0.5%CVE-2020-5991NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write opEPSS 0.5%CVE-2026-24186HIGHNVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBEPSS 0.5%CVE-2026-24164HIGHNVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerabiEPSS 0.5%