Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

National Instruments

First CVE: Aug 6, 2013Active for: 13 yearsTotal CVEs: 90
44.3
VTI Score
High

National Instruments maintains a focused portfolio of engineering design, simulation, and data-acquisition software used widely in research, industrial control, and embedded systems development. Despite the modest product count, the vendor's prominence in the critical infrastructure and embedded systems landscape means its vulnerabilities have broad downstream reach. The recurring exposure centers on memory-safety issues such as out-of-bounds writes and reads, improper index validation, and path-traversal weaknesses across products including LabVIEW, DAQmx, Circuit Design Suite, VeriStand, and FlexLogger—threat classes typical of native-code instruments and design tools that process untrusted files and configuration inputs. Defenders tracking this vendor should prioritize inventorying integrated systems and automated test platforms that depend on these design tools, as patching often requires coordinated engineering workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
90
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by National Instruments over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2013
12 years ago
Most Recent CVE
Jun 19, 2026
35 days ago

Self-Reporting Analysis

Of all the CVEs published by National Instruments as a CNA, 89.2% affect products that National Instruments develops as a vendor.

89.2%
10.8%
Self-reported: 74 (89.2%)
Third-party: 9 (10.8%)

Of all the CVEs published that affect products developed by National Instruments, 82.2% are self-published by National Instruments as a CNA.

82.2%
17.8%
Self-published: 74 (82.2%)
Other CNAs: 16 (17.8%)

Products(26 total)

Top CVEs

Signals from CVEs in this vendor scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-2449HIGH
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected inst
Mar 18, 20258.841NONO
CVE-2026-48137CRITICAL
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentiall
Jun 19, 20269.839NONO
CVE-2026-9142CRITICAL
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthent
Jun 19, 20269.138NONO
CVE-2026-8036HIGH
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects
Jun 2, 20267.833NONO
CVE-2026-48139HIGH
There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash.  Succ
Jun 19, 20267.530NONO
CVE-2026-48138HIGH
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requi
Jun 19, 20267.530NONO
CVE-2024-6793CRITICAL
A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker
Jul 22, 20249.830NONO
CVE-2024-6806CRITICAL
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affect
Jul 22, 20249.829NONO
CVE-2013-5022HIGH
Absolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and
Aug 6, 201310.029NONO
CVE-2026-48141HIGH
There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion.  This affects NI grpc-device 2.17.0 and prior versions.
Jun 19, 20267.528NONO
View all 90 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products90 CVEs
11%
81%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local67 (74.4%)
Network16 (17.8%)
Unknown6 (6.7%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low84 (93.3%)
High0 (0.0%)
Unknown6 (6.7%)
User Interaction
None28 (31.1%)
Unknown6 (6.7%)
Required56 (62.2%)
Privileges Required
Low15 (16.7%)
High0 (0.0%)
None69 (76.7%)
Unknown6 (6.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by National Instruments.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by National Instruments — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For National Instruments's Products

View all 5 CNAs →

Top CWEs