LIVE · cybersecurity feed
Live wire
vendor

Nvidia

103 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical5
High98
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-650839.9criticalopenshellNVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause11d ago
CVE-2026-650939.9criticalopenshellNVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.11d ago
CVE-2026-476279.8criticaltriton inference serverNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal.18d ago
CVE-2026-242079.8criticaltriton inference serverNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.109d ago
CVE-2026-242549.8criticaldynamoNVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause32d ago
CVE-2026-241878.8highgpu display driverNVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free.102d ago
CVE-2026-650918.8highopenshellNVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injec11d ago
CVE-2026-242178.8highbionemo frameworkNVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a mali108d ago
CVE-2026-650928.5highopenshellNVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass 11d ago
CVE-2026-476238.2highdynamoNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data.32d ago
CVE-2026-241888.2hightensorrtNVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write.108d ago
CVE-2026-242538.2highdynamoNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write.32d ago
CVE-2026-650848.1highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improp11d ago
CVE-2026-650818.1highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause exec11d ago
CVE-2026-242188.1highdgx osNVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image caus108d ago
CVE-2026-651058.1highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may acce11d ago
CVE-2026-650988.1highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could c11d ago
CVE-2026-242138hightriton inference serverNVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-o109d ago
CVE-2026-242148hightriton inference serverNVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integ109d ago
CVE-2026-242487.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code g66d ago
CVE-2026-242497.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrust66d ago
CVE-2026-242507.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of all66d ago
CVE-2026-242517.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynami66d ago
CVE-2026-242387.8hightensorrtNVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index.53d ago
CVE-2026-242687.8hightensorrtNVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow.53d ago
CVE-2026-242727.8hightensorrtNVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer.53d ago
CVE-2026-242527.8highnemoNVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection.40d ago
CVE-2026-617797.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-242167.8highbionemo frameworkNVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data.108d ago
CVE-2026-241627.8hightransformers4recNVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization 102d ago
CVE-2026-241907.8highgpu display driverNVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could 102d ago
CVE-2026-241917.8highgpu display driverNVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-u102d ago
CVE-2026-241927.8highgpu display driverNVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion bet102d ago
CVE-2026-241937.8highgpu display driverNVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bound102d ago
CVE-2026-241947.8highgpu display driverNVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause 102d ago
CVE-2026-242217.8highnvtabularNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data95d ago
CVE-2026-242377.8highnvtabularNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data95d ago
CVE-2026-241557.8highnemoNVIDIA NeMo Framework for all platforms contains a code injection vulnerability.81d ago
CVE-2026-242287.8highnemoNVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted 81d ago
CVE-2026-242407.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrust66d ago
CVE-2026-242427.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forger66d ago
CVE-2026-242437.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrust66d ago
CVE-2026-242447.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrust66d ago
CVE-2026-242457.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrust66d ago
CVE-2026-242467.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynami66d ago
CVE-2026-242477.8highnemo megatron bridgeNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrust66d ago
CVE-2026-617567.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617577.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617587.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617597.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617607.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617617.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617627.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617637.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617647.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617657.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617667.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617677.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617687.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617697.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617707.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617717.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617727.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617737.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617747.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617757.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617767.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617777.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617787.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-241837.8highcumulus linuxNVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could u18d ago
CVE-2026-650897.8highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could11d ago
CVE-2026-650907.8highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause 11d ago
CVE-2026-650967.8highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause11d ago
CVE-2026-650997.8highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS11d ago
CVE-2026-617507.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617517.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617527.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617537.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617547.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2026-617557.8highnemo megatron bridgeNVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data.4d ago
CVE-2025-332557.5hightensorrt llmNVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe de109d ago
CVE-2026-476137.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to 32d ago
CVE-2026-476147.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery.32d ago
CVE-2026-476157.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supply32d ago
CVE-2026-476167.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause serve32d ago
CVE-2026-476177.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause serve32d ago
CVE-2026-476187.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could caus32d ago
CVE-2026-242557.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause 32d ago
CVE-2026-650977.5highnemoclawNVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a do11d ago
CVE-2026-241847.5highcumulus linuxNVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where 18d ago
CVE-2026-474767.5hightriton inference serverNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resourc53d ago
CVE-2026-476287.5hightriton inference serverNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of r18d ago
CVE-2026-476297.5hightriton inference serverNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input val18d ago
CVE-2026-242647.5hightriton inference serverNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of66d ago
CVE-2026-241637.5hightensorrt llmNVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe d109d ago
CVE-2026-242107.5hightriton inference serverNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow.109d ago
CVE-2026-242097.5hightriton inference serverNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue.109d ago
CVE-2026-476127.5highdynamoNVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improp32d ago
CVE-2026-242127.5highisaac launchableNVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear tex102d ago
CVE-2026-242067.3hightriton inference serverNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.109d ago

Filter the full tracker by Nvidia

Our coverage of Nvidia

security

New GPUThor attack defeats NVIDIA ECC protection for root access

A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]

CVE-2024-28224high

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A vulnerability in NVIDIA NemoClaw could allow a malicious webpage to hijack a local AI agent by modifying its chat template. This could lead to hidden instructions being injected into the AI model, affecting all future conversations. While fixes are available for macOS and Linux, Windows and WSL paths remain vulnerable.