Nvflare
Vendor:
First CVE: Jul 1, 2022 · Active for 4 years
6
Total CVEs
More Total CVEs than 80% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nvflare over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2022
4 years ago
Most Recent CVE
Apr 28, 2026
87 days ago
CVE Severity & Scoring
Nvflare6 CVEs
17%
17%
67%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34668CRITICAL NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Cod | Aug 29, 2022 | 9.8 | 46 | NO | YES |
CVE-2026-24178CRITICAL NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-con | Apr 28, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-24186HIGH NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit | Apr 28, 2026 | 8.8 | 34 | NO | NO |
CVE-2022-31605CRITICAL NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untr | Jul 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-31604CRITICAL NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The de | Jul 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-24204MEDIUM NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to inform | Apr 28, 2026 | 6.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Nvflare
Top CWEs
Versions
No cataloged versions.