VulnSea

nvidia has 24 CVEs on record. Cadence is steady at roughly 12 per quarter. The busiest recent month was August 2026 with 9. The median CVSS is 7.8 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-502 (4) and CWE-787 (4). Most affected products: dgx_spark_uefi (5), bionemo_framework (4), dynamo (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
12 prev 10

Products

  • dgx_spark_uefi 5
  • bionemo_framework 4
  • dynamo 4
  • jetson_linux 3
  • Triton Inference Server 2
  • nemo_megatron_bridge 2
24
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

nvidia vulnerabilities

CVEs affecting nvidia, newest first. Open any entry for full detail, references, and exploit status.

24 CVEsRSS

CVE-2026-47625High· 7.5
2w ago

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

TwilightNVIDIA · Triton Inference ServerEPSS 0.40%via NVD
CVE-2026-16497High· 7.5
2w ago

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.

TwilightNVIDIA · Triton Inference ServerEPSS 0.43%via NVD
CVE-2026-47624Medium· 6.0
4w ago

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.

Sunlitnvidia · dgx_spark_uefiEPSS 0.18%via NVD
CVE-2026-24262High· 8.2
4w ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges,…

Twilightnvidia · dgx_spark_uefiEPSS 0.20%via NVD
CVE-2026-47626High· 8.2
4w ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges,…

Twilightnvidia · dgx_spark_uefiEPSS 0.20%via NVD
CVE-2026-24263High· 8.2
4w ago

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privile…

Twilightnvidia · dgx_spark_uefiEPSS 0.20%via NVD
CVE-2026-24225Medium· 6.0
4w ago

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read

NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.

Sunlitnvidia · dgx_spark_uefiEPSS 0.18%via NVD
CVE-2026-47612High· 7.5
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information…

Twilightnvidia · dynamoEPSS 0.55%via NVD
CVE-2026-24255High· 7.5
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successf…

Twilightnvidia · dynamoEPSS 0.38%via NVD
CVE-2026-24254Critical· 9.8
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…

Midnightnvidia · dynamoEPSS 0.54%via NVD
CVE-2026-24253High· 8.2
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.

Twilightnvidia · dynamoEPSS 0.35%via NVD
CVE-2026-24252High· 7.8
1mo ago

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

Twilightnvidia · nemoEPSS 0.88%via NVD
CVE-2026-24218High· 8.1
4mo ago

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all sim…

Twilightnvidia · dgx_osEPSS 0.60%via NVD
CVE-2026-24217High· 8.8
4mo ago

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclos…

Twilightnvidia · bionemo_frameworkEPSS 0.76%via NVD
CVE-2026-24216High· 7.8
4mo ago

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data …

Twilightnvidia · bionemo_frameworkEPSS 0.29%via NVD
CVE-2026-24188High· 8.2
4mo ago

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

Twilightnvidia · tensorrtEPSS 0.39%via NVD
CVE-2026-24156High· 7.3
5mo ago

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

Twilightnvidia · data_loading_libraryEPSS 0.26%via NVD
CVE-2026-24165High· 7.8
5mo ago

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Twilightnvidia · bionemo_frameworkEPSS 0.31%via NVD
CVE-2026-24164High· 8.8
5mo ago

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Twilightnvidia · bionemo_frameworkEPSS 0.47%via NVD
CVE-2026-24154High· 7.6
5mo ago

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of pri…

Twilightnvidia · jetson_linuxEPSS 0.26%via NVD
CVE-2026-24153Medium· 5.2
5mo ago

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

Sunlitnvidia · jetson_linuxEPSS 0.12%via NVD
CVE-2026-24148High· 8.3
5mo ago

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might…

Twilightnvidia · jetson_linuxEPSS 0.35%via NVD
CVE-2025-33240High· 7.8
7mo ago

NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection

NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat…

Twilightnvidia · nemo_megatron_bridgeEPSS 0.21%via NVD
CVE-2025-33239High· 7.8
7mo ago

NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection

NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informatio…

Twilightnvidia · nemo_megatron_bridgeEPSS 0.21%via NVD
nvidia vulnerabilities (CVEs) · VulnSea