Cuda Toolkit
Vendor:
First CVE: Jan 22, 2011 · Active for 15 years
46
Total CVEs
More Total CVEs than 97% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cuda Toolkit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2011
15 years ago
Most Recent CVE
Jan 20, 2026
185 days ago
CVE Severity & Scoring
Cuda Toolkit46 CVEs
57%
22%
22%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local45 (97.8%)
Network0 (0.0%)
Unknown1 (2.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (93.5%)
High2 (4.3%)
Unknown1 (2.2%)
User Interaction
None7 (15.2%)
Unknown1 (2.2%)
Required38 (82.6%)
Privileges Required
Low13 (28.3%)
High0 (0.0%)
None32 (69.6%)
Unknown1 (2.2%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-33228HIGH NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_ | Jan 20, 2026 | 7.3 | 28 | NO | NO |
CVE-2025-23339HIGH NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a mali | Sep 24, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-33229HIGH NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual | Jan 20, 2026 | 7.3 | 25 | NO | NO |
CVE-2022-21821HIGH NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially | Mar 29, 2022 | 7.8 | 25 | NO | NO |
CVE-2025-33230HIGH NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the install | Jan 20, 2026 | 7.3 | 24 | NO | NO |
CVE-2025-23308HIGH NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicio | Sep 24, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-33231MEDIUM NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploitin | Jan 20, 2026 | 6.7 | 23 | NO | NO |
CVE-2025-23275HIGH NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain image dimensions. | Sep 24, 2025 | 7.1 | 23 | NO | NO |
CVE-2024-0110HIGH NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A successful exploit of this vu | Aug 31, 2024 | 7.8 | 23 | NO | NO |
CVE-2025-23247HIGH NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to cras | May 27, 2025 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Cuda Toolkit
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2 | 1 | 2.1 | 0.4% | 0 | 0 |