NVIDIA records
912 published records for vendor nvidia.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.1%
- Pre-auth RCE
- 24
- With a fix record
- 14.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data77
- CWE-20 Improper Input Validation71
- CWE-476 NULL Pointer Dereference63
- CWE-125 Out-of-bounds Read48
- CWE-787 Out-of-bounds Write44
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer43
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
- NVIDIA Public Bug BountyIntigriti · paid · up to $15,000
- NVIDIA Vulnerability Disclosure ProgramIntigriti · disclosure only (VDP)
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
912 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2017-14491Proof of concept | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Critical9.8 | — | 84.9% | Oct 3, 2017 |
45Plan | CVE-2024-0132Proof of concept | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration nvidia · nvidia container toolkit · CWE-367 | High8.3 | — | 40.8% | Sep 26, 2024 |
42Plan | CVE-2022-34668Proof of concept | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivilenvidia · nvflare · CWE-502 | Critical9.8 | — | 10.9% | Aug 28, 2022 |
42Plan | CVE-2019-5684No exploit | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause nvidia · gpu driver · CWE-787 | Critical10.0 | — | 5.4% | Aug 6, 2019 |
41Plan | CVE-2024-0087No exploit | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.nvidia · triton inference server · CWE-73 | High8.8 | — | 19.9% | May 14, 2024 |
41Plan | CVE-2019-5685No exploit | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause nvidia · gpu driver · CWE-787 | Critical9.8 | — | 5.0% | Aug 6, 2019 |
41Plan | CVE-2013-5986No exploit | Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different vnvidia · gpu driver | Critical10.0 | — | 1.8% | Jan 21, 2014 |
41Plan | CVE-2015-5053No exploit | The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 3nvidia · gpu driver · CWE-284 | Critical10.0 | — | 1.7% | Nov 24, 2015 |
40Plan | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Medium5.5 | — | 60.6% | May 22, 2018 |
40Plan | CVE-2020-11486No exploit | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwarenvidia · dgx-1 · CWE-434 | Critical9.8 | — | 2.7% | Oct 29, 2020 |
40Plan | CVE-2025-23311No exploit | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requesnvidia · triton inference server · CWE-121 | Critical9.8 | — | 2.6% | Aug 6, 2025 |
40Plan | CVE-2026-24207Proof of concept | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.nvidia · triton inference server · CWE-288 | Critical9.8 | — | 2.6% | May 20, 2026 |
40Plan | CVE-2026-65130No exploit | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection.nvidia · infra controller · CWE-78 | Critical9.8 | — | 2.1% | Sep 22, 2026 |
40Plan | CVE-2022-31604No exploit | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pinvidia · nvflare · CWE-502 | Critical9.8 | — | 2.1% | Jul 1, 2022 |
40Plan | CVE-2022-31605No exploit | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.nvidia · nvflare · CWE-502 | Critical9.8 | — | 2.1% | Jul 1, 2022 |
40Plan | CVE-2025-23317No exploit | NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specinvidia · triton inference server · CWE-122 | Critical9.8 | — | 2.0% | Aug 6, 2025 |
40Plan | CVE-2025-23242No exploit | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue.nvidia · riva · CWE-284 | Critical9.8 | — | 1.9% | Mar 11, 2025 |
40Plan | CVE-2025-23310No exploit | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specialnvidia · triton inference server · CWE-121 | Critical9.8 | — | 1.9% | Aug 6, 2025 |
40Plan | CVE-2019-15788No exploit | Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.nvidia · clara genomics analysis · CWE-190 | Critical9.8 | — | 1.8% | Aug 29, 2019 |
39Monitor | CVE-2025-23319No exploit | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofnvidia · triton inference server · CWE-805 | Critical9.8 | — | 1.6% | Aug 6, 2025 |
39Monitor | CVE-2020-11483No exploit | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, containnvidia · dgx-1 · CWE-798 | Critical9.8 | — | 1.4% | Oct 29, 2020 |
39Monitor | CVE-2022-28181No exploit | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on thenvidia · virtual gpu · CWE-787 | Critical9.9 | — | 1.1% | May 17, 2022 |
39Monitor | CVE-2025-23304No exploit | NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection nvidia · nemo · CWE-22 | Critical9.8 | — | 1.1% | Aug 13, 2025 |
39Monitor | CVE-2026-24227No exploit | NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.nvidia · tensorrt · CWE-502 | Critical9.8 | — | 1.0% | Jul 14, 2026 |
39Monitor | CVE-2026-65098No exploit | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.nvidia · nemoclaw · CWE-1390 | Critical9.8 | — | 1.0% | Aug 25, 2026 |
- CVE-2017-1449164This week
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
CriticalCVSS 9.8Proof of conceptEPSS 85%thekelleys · dnsmasqOct 3, 2017
- CVE-2024-013245Plan
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration
HighCVSS 8.3Proof of conceptEPSS 41%nvidia · nvidia container toolkitSep 26, 2024
- CVE-2022-3466842Plan
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivile
CriticalCVSS 9.8Proof of conceptEPSS 11%nvidia · nvflareAug 28, 2022
- CVE-2019-568442Plan
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause
CriticalCVSS 10.0No exploitEPSS 5%nvidia · gpu driverAug 6, 2019
- CVE-2024-008741Plan
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.
HighCVSS 8.8No exploitEPSS 20%nvidia · triton inference serverMay 14, 2024
- CVE-2019-568541Plan
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause
CriticalCVSS 9.8No exploitEPSS 5%nvidia · gpu driverAug 6, 2019
- CVE-2013-598641Plan
Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different v
CriticalCVSS 10.0No exploitEPSS 2%nvidia · gpu driverJan 21, 2014
- CVE-2015-505341Plan
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 3
CriticalCVSS 10.0No exploitEPSS 2%nvidia · gpu driverNov 24, 2015
- CVE-2018-363940Plan
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
MediumCVSS 5.5Proof of conceptEPSS 61%intel · atom cMay 22, 2018
- CVE-2020-1148640Plan
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software
CriticalCVSS 9.8No exploitEPSS 3%nvidia · dgx-1Oct 29, 2020
- CVE-2025-2331140Plan
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP reques
CriticalCVSS 9.8No exploitEPSS 3%nvidia · triton inference serverAug 6, 2025
- CVE-2026-2420740Plan
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.
CriticalCVSS 9.8Proof of conceptEPSS 3%nvidia · triton inference serverMay 20, 2026
- CVE-2026-6513040Plan
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection.
CriticalCVSS 9.8No exploitEPSS 2%nvidia · infra controllerSep 22, 2026
- CVE-2022-3160440Plan
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pi
CriticalCVSS 9.8No exploitEPSS 2%nvidia · nvflareJul 1, 2022
- CVE-2022-3160540Plan
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.
CriticalCVSS 9.8No exploitEPSS 2%nvidia · nvflareJul 1, 2022
- CVE-2025-2331740Plan
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a speci
CriticalCVSS 9.8No exploitEPSS 2%nvidia · triton inference serverAug 6, 2025
- CVE-2025-2324240Plan
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue.
CriticalCVSS 9.8No exploitEPSS 2%nvidia · rivaMar 11, 2025
- CVE-2025-2331040Plan
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by special
CriticalCVSS 9.8No exploitEPSS 2%nvidia · triton inference serverAug 6, 2025
- CVE-2019-1578840Plan
Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
CriticalCVSS 9.8No exploitEPSS 2%nvidia · clara genomics analysisAug 29, 2019
- CVE-2025-2331939Monitor
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of
CriticalCVSS 9.8No exploitEPSS 2%nvidia · triton inference serverAug 6, 2025
- CVE-2020-1148339Monitor
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain
CriticalCVSS 9.8No exploitEPSS 1%nvidia · dgx-1Oct 29, 2020
- CVE-2022-2818139Monitor
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the
CriticalCVSS 9.9No exploitEPSS 1%nvidia · virtual gpuMay 17, 2022
- CVE-2025-2330439Monitor
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection
CriticalCVSS 9.8No exploitEPSS 1%nvidia · nemoAug 13, 2025
- CVE-2026-2422739Monitor
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.
CriticalCVSS 9.8No exploitEPSS 1%nvidia · tensorrtJul 14, 2026
- CVE-2026-6509839Monitor
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.
CriticalCVSS 9.8No exploitEPSS 1%nvidia · nemoclawAug 25, 2026