NVIDIA Corporation
First CVE: Nov 8, 2016Active for: 10 years
952
CVEs Published
More CVEs Published than 91% of tracked CNAs
86.5
Avg CVEs / Year
More Avg CVEs / Year than 89% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by NVIDIA Corporation as a CNA, 79.9% affect products that NVIDIA Corporation develops as a vendor.
79.9%
20.1%
Self-reported: 761Third-party: 191
Of all the CVEs published that affect products developed by NVIDIA Corporation, 94.4% are self-published by NVIDIA Corporation as a CNA.
94.4%
Self-published: 761Published by other CNAs: 45
Trends Over Time
The number and severity of CVEs published by NVIDIA Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2016
9 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by NVIDIA Corporation as a CNA, regardless of affected vendor or product.
952 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0132HIGH NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container i | Sep 26, 2024 | 8.3 | 61 | NO | YES |
CVE-2026-24207CRITICAL NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execut | May 20, 2026 | 9.8 | 51 | NO | YES |
CVE-2022-34668CRITICAL NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Cod | Aug 29, 2022 | 9.8 | 46 | NO | YES |
CVE-2026-24270CRITICAL NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalat | Jul 1, 2026 | 9.8 | 41 | NO | NO |
CVE-2025-23351CRITICAL NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input | Jul 1, 2026 | 9.0 | 39 | NO | NO |
CVE-2026-24227CRITICAL NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution. | Jul 14, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-23350CRITICAL NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input | Jul 1, 2026 | 9.0 | 38 | NO | NO |
CVE-2026-24178CRITICAL NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-con | Apr 28, 2026 | 9.8 | 38 | NO | NO |
CVE-2024-0087HIGH NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file | May 14, 2024 | 8.8 | 38 | NO | NO |
CVE-2026-24233HIGH NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deseri | Jul 14, 2026 | 8.4 | 37 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA952 CVEs
29%
60%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local729 (76.6%)
Network193 (20.3%)
Unknown0 (0.0%)
Physical13 (1.4%)
Adjacent Network17 (1.8%)
Attack Complexity
Low872 (91.6%)
High80 (8.4%)
Unknown0 (0.0%)
User Interaction
None801 (84.1%)
Unknown0 (0.0%)
Required151 (15.9%)
Privileges Required
Low609 (64.0%)
High80 (8.4%)
None263 (27.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (952 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.1% of CVEs· 70th percentile
ExploitDB
18 CVEs
1.9% of CVEs· 88th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by NVIDIA Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by NVIDIA Corporation as a CNA — matched by CVE ID, not by organization name.