Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | EPSS | KEV sources | Patch window | Vendor / product | Summary | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65093 | 9.9 | — | — | — | nvidia / openshell | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. | 11d ago |
| CVE-2026-65083 | 9.9 | — | — | — | nvidia / openshell | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause | 11d ago |
| CVE-2026-47627 | 9.8 | — | — | — | nvidia / triton inference server | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. | 18d ago |
| CVE-2026-24254 | 9.8 | — | — | — | nvidia / dynamo | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause | 32d ago |
| CVE-2026-24207 | 9.8 | — | — | — | nvidia / triton inference server | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. | 109d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE); CISA KEV, ENISA EUVD, CIRCL and VulnCheck (exploitation status, four independent catalogues); FIRST EPSS (exploitation probability). Patch window is the gap between CVE publication and the earliest KEV listing, so a negative value means a catalogue called it exploited before it was disclosed. Data refreshes every five hours.