Nvidia Security Vulnerabilities (CVEs)

Track 124 security vulnerabilities affecting Nvidia products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

9 Critical
94 High
21 Medium
🔔 Get Alerts for Nvidia
CVE-2026-24241 4.3

NVIDIA Delegated Licensing Service contains an improper authentication vulnerability (CWE-287) that could allow an attacker to bypass authentication m...

Feb 24, 2026
CVE-2025-33181 7.3

This vulnerability allows low-privileged users on NVIDIA Cumulus Linux and NVOS systems to inject commands through the NVUE interface, potentially lea...

Feb 24, 2026
CVE-2025-33179 8.0

This vulnerability in NVIDIA Cumulus Linux and NVOS allows low-privileged users to execute unauthorized commands through the NVUE interface, potential...

Feb 24, 2026
CVE-2025-33252 7.8

CVE-2025-33252 is a deserialization vulnerability in NVIDIA's NeMo Framework that allows remote attackers to execute arbitrary code. This affects orga...

Feb 18, 2026
CVE-2025-33243 7.8

The NVIDIA NeMo Framework vulnerability allows remote code execution in distributed environments, enabling attackers to execute arbitrary code, escala...

Feb 18, 2026
CVE-2025-33246 7.8

CVE-2025-33246 is a command injection vulnerability in NVIDIA's NeMo Framework ASR Evaluator utility that allows attackers to execute arbitrary comman...

Feb 18, 2026
CVE-2025-33250 7.8

CVE-2025-33250 is a remote code execution vulnerability in NVIDIA's NeMo Framework that allows attackers to execute arbitrary code on affected systems...

Feb 18, 2026
CVE-2025-33236 7.8

The NVIDIA NeMo Framework vulnerability allows attackers to inject malicious code through crafted data inputs. Successful exploitation could lead to r...

Feb 18, 2026
CVE-2025-33240 7.8

NVIDIA Megatron Bridge contains a code injection vulnerability in a data shuffling tutorial component. Successful exploitation could allow attackers t...

Feb 18, 2026
CVE-2025-33228 7.3

NVIDIA Nsight Systems contains an OS command injection vulnerability in the gfx_hotspot recipe. Attackers can execute arbitrary commands by supplying ...

Jan 20, 2026
CVE-2025-33229 7.3

This vulnerability in NVIDIA Nsight Visual Studio for Windows allows attackers to execute arbitrary code with the same privileges as the Nsight Monito...

Jan 20, 2026
CVE-2025-33230 7.3

This vulnerability allows attackers to execute arbitrary operating system commands by injecting malicious strings into the installation path parameter...

Jan 20, 2026
CVE-2025-33231 6.7

CVE-2025-33231 is a DLL hijacking vulnerability in NVIDIA Nsight Systems for Windows that allows attackers to execute arbitrary code by placing malici...

Jan 20, 2026
CVE-2025-33206 7.8

This CVE describes a command injection vulnerability in NVIDIA NSIGHT Graphics for Linux that allows attackers to execute arbitrary commands. Successf...

Jan 14, 2026
CVE-2025-33211 7.5

NVIDIA Triton Server for Linux has an input validation vulnerability where attackers can trigger improper quantity validation, potentially causing den...

Dec 3, 2025
CVE-2025-33201 7.5

NVIDIA Triton Inference Server has a vulnerability where sending excessively large payloads can trigger improper condition checking, potentially causi...

Dec 3, 2025
CVE-2025-33208 8.8

This vulnerability in NVIDIA TAO allows attackers to load malicious resources via uncontrolled search paths, potentially leading to privilege escalati...

Dec 3, 2025
CVE-2025-33205 7.3

The NVIDIA NeMo framework contains a vulnerability where attackers can exploit a predefined variable to include functionality from untrusted sources, ...

Nov 25, 2025
CVE-2025-33194 5.7

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to exploit improper input processing. Successful exploitation could lead...

Nov 25, 2025
CVE-2025-33196 4.4

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows resource reuse, potentially enabling information disclosure. Attackers could explo...

Nov 25, 2025
CVE-2025-33197 4.3

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to trigger a NULL pointer dereference, potentially causing a denial of s...

Nov 25, 2025
CVE-2025-33188 8.0

This vulnerability in NVIDIA DGX Spark GB10 hardware allows attackers to tamper with hardware controls, potentially leading to information disclosure,...

Nov 25, 2025
CVE-2025-33189 7.8

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to perform out-of-bounds writes, potentially leading to code execution, ...

Nov 25, 2025
CVE-2025-33191 5.7

This vulnerability in NVIDIA DGX Spark GB10's OSROOT firmware allows attackers to trigger invalid memory reads, potentially causing denial of service....

Nov 25, 2025
CVE-2025-33193 5.7

NVIDIA DGX Spark GB10 systems contain a vulnerability in SROOT firmware where improper integrity validation could allow attackers to access sensitive ...

Nov 25, 2025
CVE-2025-33187 9.3

This vulnerability in NVIDIA DGX Spark GB10's SROOT component allows attackers with privileged access to bypass SoC (System-on-Chip) protections. Succ...

Nov 25, 2025
CVE-2025-33178 7.8

The NVIDIA NeMo Framework contains a code injection vulnerability in its BERT services component that allows attackers to execute arbitrary code by se...

Nov 11, 2025
CVE-2025-33202 6.5

NVIDIA Triton Inference Server contains a stack overflow vulnerability where attackers can send extra-large payloads to cause denial of service. This ...

Nov 11, 2025
CVE-2025-23361 7.8

The NVIDIA NeMo Framework contains a vulnerability where malicious input can cause improper control of code generation, potentially leading to remote ...

Nov 11, 2025
CVE-2025-23355 6.7

This vulnerability in NVIDIA Nsight Graphics for Windows allows DLL hijacking attacks where an attacker could place a malicious DLL in a location that...

Oct 1, 2025
CVE-2025-23353 7.8

NVIDIA Megatron-LM's msdp preprocessing script contains a code injection vulnerability (CWE-94) that allows attackers to execute arbitrary code by pro...

Sep 24, 2025
CVE-2025-23348 7.8

CVE-2025-23348 is a code injection vulnerability in NVIDIA's Megatron-LM pretrain_gpt script that allows attackers to execute arbitrary code by provid...

Sep 24, 2025
CVE-2025-23275 4.2

This vulnerability in NVIDIA CUDA Toolkit's nvJPEG component allows a local authenticated user to trigger a GPU out-of-bounds write by providing speci...

Sep 24, 2025
CVE-2025-23343 7.6

The NVIDIA NVDebug tool contains a improper path validation vulnerability (CWE-22) that allows attackers to write files to restricted system component...

Sep 9, 2025
CVE-2025-23315 7.8

CVE-2025-23315 is a code injection vulnerability in NVIDIA NeMo Framework's export and deploy component that allows attackers to execute arbitrary cod...

Aug 26, 2025
CVE-2025-23307 7.8

NVIDIA NeMo Curator contains a code injection vulnerability (CWE-94) where malicious files can execute arbitrary code. This affects all platforms runn...

Aug 26, 2025
CVE-2025-23313 7.8

CVE-2025-23313 is a code injection vulnerability in NVIDIA's NeMo Framework NLP component that allows attackers to execute arbitrary code by providing...

Aug 26, 2025
CVE-2025-23333 5.9

CVE-2025-23333 is an out-of-bounds read vulnerability in NVIDIA Triton Inference Server's Python backend that allows attackers to read memory beyond a...

Aug 6, 2025
CVE-2025-23334 5.9

CVE-2025-23334 is an out-of-bounds read vulnerability in NVIDIA Triton Inference Server's Python backend that could allow information disclosure. Atta...

Aug 6, 2025
CVE-2025-23335 4.4

NVIDIA Triton Inference Server contains an integer underflow vulnerability in its TensorRT backend that could allow attackers to cause denial of servi...

Aug 6, 2025
CVE-2025-23323 7.5

NVIDIA Triton Inference Server contains an integer overflow vulnerability where sending an invalid request can cause a segmentation fault and crash th...

Aug 6, 2025
CVE-2025-23325 7.5

NVIDIA Triton Inference Server contains a vulnerability where specially crafted inputs can trigger uncontrolled recursion, potentially causing denial ...

Aug 6, 2025
CVE-2025-23327 7.5

NVIDIA Triton Inference Server contains an integer overflow vulnerability (CWE-190) where specially crafted inputs could cause denial of service or da...

Aug 6, 2025
CVE-2025-23317 9.1

NVIDIA Triton Inference Server's HTTP server has a heap-based buffer overflow vulnerability (CWE-122) that allows attackers to execute arbitrary code ...

Aug 6, 2025
CVE-2025-23319 8.1

NVIDIA Triton Inference Server's Python backend has a buffer overflow vulnerability where specially crafted requests can trigger out-of-bounds writes....

Aug 6, 2025
CVE-2025-23321 7.5

NVIDIA Triton Inference Server contains a divide-by-zero vulnerability in request processing that could cause denial of service. Attackers can exploit...

Aug 6, 2025
CVE-2025-23310 9.8

CVE-2025-23310 is a critical stack buffer overflow vulnerability in NVIDIA Triton Inference Server that allows attackers to execute arbitrary code rem...

Aug 6, 2025
CVE-2025-23265 7.8

CVE-2025-23265 is a code injection vulnerability in NVIDIA Megatron-LM's Python component that allows attackers to execute arbitrary code by providing...

Jun 24, 2025
CVE-2025-23252 4.5

The NVIDIA NVDebug tool contains a vulnerability that could allow attackers to access restricted components, potentially leading to information disclo...

Jun 18, 2025
CVE-2025-23249 7.6

The NVIDIA NeMo Framework vulnerability allows remote attackers to execute arbitrary code by exploiting insecure deserialization of untrusted data. Th...

Apr 22, 2025

Why Monitor Nvidia Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 124+ known vulnerabilities affecting Nvidia products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Nvidia packages in under 60 seconds. No agents required - completely agentless scanning that works across Nvidia deployments.

Free vulnerability database: Access detailed information about every Nvidia CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Nvidia CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Nvidia CVEs Free