VulnSea

NVIDIA has 44 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 10 in the 90 before. The busiest recent month was September 2026 with 21. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-502 (9) and CWE-787 (4). Most affected products: Infrastructure Controller (14), NeMo Speech (5), dgx_spark_uefi (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
32 prev 10

Products

  • Infrastructure Controller 14
  • NeMo Speech 5
  • dgx_spark_uefi 5
  • bionemo_framework 4
  • dynamo 4
  • jetson_linux 3
44
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

NVIDIA vulnerabilities

CVEs affecting NVIDIA, newest first. Open any entry for full detail, references, and exploit status.

44 CVEsRSS

CVE-2026-24239High· 7.8
today

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure,…

TwilightNVIDIA · NeMo Speechvia NVD
CVE-2026-65111High· 7.8
today

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and…

TwilightNVIDIA · NeMo Speechvia NVD
CVE-2026-24267High· 7.8
today

NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution

NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to …

TwilightNVIDIA · NeMo Speechvia NVD
CVE-2026-65179High· 8.8
today

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execut…

TwilightNVIDIA · NeMo Speechvia NVD
CVE-2026-65178High· 7.8
today

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denia…

TwilightNVIDIA · NeMo Speechvia NVD
CVE-2026-65128High· 8.8
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information …

TwilightNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65124Medium· 5.9
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65121High· 8.2
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosur…

TwilightNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65127Medium· 4.1
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to infor…

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65126Medium· 5.0
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, …

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65129Medium· 6.7
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denia…

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65125Medium· 6.6
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65113Critical· 9.8
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of…

MidnightNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65130High· 8.0
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and infor…

TwilightNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65115Medium· 6.5
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65114High· 8.3
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service,…

TwilightNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65118High· 7.5
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denia…

TwilightNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65117Medium· 5.0
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information d…

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-65112Medium· 6.5
today

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

SunlitNVIDIA · Infrastructure Controllervia NVD
CVE-2026-47625High· 7.5
2w ago

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

TwilightNVIDIA · Triton Inference ServerEPSS 0.40%via NVD
CVE-2026-16497High· 7.5
2w ago

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.

TwilightNVIDIA · Triton Inference ServerEPSS 0.43%via NVD
CVE-2026-47624Medium· 6.0
4w ago

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.

Sunlitnvidia · dgx_spark_uefiEPSS 0.18%via NVD
CVE-2026-24262High· 8.2
4w ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges,…

Twilightnvidia · dgx_spark_uefiEPSS 0.20%via NVD
CVE-2026-47626High· 8.2
4w ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges,…

Twilightnvidia · dgx_spark_uefiEPSS 0.20%via NVD
CVE-2026-24263High· 8.2
4w ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privile…

Twilightnvidia · dgx_spark_uefiEPSS 0.20%via NVD
CVE-2026-24225Medium· 6.0
4w ago

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.

Sunlitnvidia · dgx_spark_uefiEPSS 0.18%via NVD
CVE-2026-47612High· 7.5
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information…

Twilightnvidia · dynamoEPSS 0.55%via NVD
CVE-2026-24255High· 7.5
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successf…

Twilightnvidia · dynamoEPSS 0.38%via NVD
CVE-2026-24254Critical· 9.8
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…

Midnightnvidia · dynamoEPSS 0.54%via NVD
CVE-2026-24253High· 8.2
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.

Twilightnvidia · dynamoEPSS 0.35%via NVD
NVIDIA vulnerabilities (CVEs) · VulnSea