Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-24220

NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24218

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of service.

PUBLISHED
Vendor
NVIDIA
Product
DGX Spark
Provider severity
HIGH
Conflicts
0

CVE-2026-24217

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

PUBLISHED
Vendor
NVIDIA
Product
BioNeMo Framework
Provider severity
HIGH
Conflicts
0

CVE-2026-24216

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

PUBLISHED
Vendor
NVIDIA
Product
BioNeMo Framework
Provider severity
HIGH
Conflicts
0

CVE-2026-24215

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24214

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24213

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24212

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

PUBLISHED
Vendor
NVIDIA
Product
Isaac Launchable
Provider severity
HIGH
Conflicts
0

CVE-2026-24210

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-2421

The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the 'cert' parameter of the 'wccd-delete-certificate' AJAX action. This is due to insufficient file path validation before performing a file deletion. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, such as wp-config.php, which can make site takeover and remote code ex

PUBLISHED
Vendor
ghera74
Product
ilGhera Carta Docente for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24209

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24208

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24207

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24206

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24204

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
FLARE SDK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24201

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24200

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager, Virtual GPU Manager
Provider severity
HIGH
Conflicts
1

CVE-2026-2420

The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the frontend of the site where the popup is displayed.

PUBLISHED
Vendor
lotekmedia
Product
LotekMedia Popup Form
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24199

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Guest driver, Guest driver, Virtual GPU Manager, GeForce, Tesla, NVIDIA RTX, Quadro, NVS, Virtual GPU Manager, GeForce, GeForce, NVIDIA RTX, Quadro, NVS, Tesla, Guest driver, NVIDIA RTX, Quadro, NVS, Virtual GPU Manager, Tesla
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24198

NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive information to an unauthorized actor. A successful exploit of this vulnerability might lead to denial of service, data tampering, and information disclosure.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Tesla, Tesla, GeForce, GeForce, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24197

NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Virtual GPU Manager, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS, Tesla, GeForce, Tesla, NVIDIA RTX, Quadro, NVS, GeForce, Virtual GPU Manager, Virtual GPU Manager, Tesla, GeForce, NVIDIA RTX, Quadro, NVS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24196

NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
GeForce, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, Guest driver, Guest driver, Guest driver, NVIDIA RTX, Quadro, NVS, GeForce, Tesla, GeForce, Tesla, Tesla, Guest driver
Provider severity
HIGH
Conflicts
1

CVE-2026-24195

NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA
Product
Guest driver, Guest driver, Guest driver
Provider severity
HIGH
Conflicts
1

CVE-2026-24194

NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Guest driver, Guest driver, NVIDIA RTX, Quadro, NVS, GeForce, NVIDIA RTX, Quadro, NVS, GeForce, Tesla, Tesla, Guest driver, Tesla, GeForce, NVIDIA RTX, Quadro, NVS, Guest driver
Provider severity
HIGH
Conflicts
1

CVE-2026-24193

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, Tesla, GeForce, GeForce, GeForce, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, Tesla, Tesla, Tesla
Provider severity
HIGH
Conflicts
1

CVE-2026-24192

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
GeForce, GeForce, GeForce, Virtual GPU Manager, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS, Tesla, NVIDIA RTX, Quadro, NVS, Virtual GPU Manager, Tesla, Tesla
Provider severity
HIGH
Conflicts
1

CVE-2026-24191

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
Guest driver, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS, Guest driver, NVIDIA RTX, Quadro, NVS, Virtual GPU Manager, Tesla, Tesla, Guest driver, Tesla, NVIDIA RTX, Quadro, NVS, GeForce, GeForce
Provider severity
HIGH
Conflicts
1

CVE-2026-24190

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, Tesla, Tesla, GeForce, GeForce, GeForce, GeForce, Tesla, Tesla, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, GeForce, NVIDIA RTX, Quadro, NVS, Tesla, Tesla
Provider severity
HIGH
Conflicts
1

CVE-2026-2419

The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CONTENT_DIR prefix check. This makes it possible for authenticated attackers, with Administrator-level access and above, to configure the plugin to list and access arbitrary files on the server by exploi

PUBLISHED
Vendor
gamerz
Product
WP-DownloadManager
Provider severity
LOW
Conflicts
0

CVE-2026-24189

NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
CUDA-Q
Provider severity
HIGH
Conflicts
0

CVE-2026-24188

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT
Provider severity
HIGH
Conflicts
0

CVE-2026-24187

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
GeForce, Guest driver, GeForce, Virtual GPU Manager, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS, Tesla, Guest driver, Tesla, Guest driver, Virtual GPU Manager, GeForce, Virtual GPU Manager, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS, Guest driver, Tesla
Provider severity
HIGH
Conflicts
1

CVE-2026-24186

NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.

PUBLISHED
Vendor
NVIDIA
Product
FLARE SDK
Provider severity
HIGH
Conflicts
0

CVE-2026-24182

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA, NVIDIA
Product
NVIDIA RTX, Quadro, NVS, Tesla, Guest driver, GeForce, GeForce, NVIDIA RTX, Quadro, NVS, Guest driver, GeForce, NVIDIA RTX, Quadro, NVS, Guest driver, Tesla, Guest driver, GeForce, Tesla, Virtual GPU Manager, GeForce, NVIDIA RTX, Quadro, NVS, Tesla, Guest driver, Guest driver, Tesla, Guest driver, Tesla, NVIDIA RTX, Quadro, NVS, NVIDIA RTX, Quadro, NVS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24181

NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
DALI
Provider severity
HIGH
Conflicts
0

CVE-2026-24180

NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
DALI
Provider severity
HIGH
Conflicts
0

CVE-2026-2418

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

PUBLISHED
Vendor
Unknown
Product
Login with Salesforce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24178

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.

PUBLISHED
Vendor
NVIDIA
Product
FLARE SDK
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24177

NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
KAI Scheduler
Provider severity
HIGH
Conflicts
0

CVE-2026-24176

NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering.

PUBLISHED
Vendor
NVIDIA
Product
KAI Scheduler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24175

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request header to the server. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24174

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-24173

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
Triton Inference Server
Provider severity
HIGH
Conflicts
0

CVE-2026-2417

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

PUBLISHED
Vendor
Pharos Controls
Product
Mosaic Show Controller
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24165

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

PUBLISHED
Vendor
NVIDIA
Product
BioNeMo Framework
Provider severity
HIGH
Conflicts
0

CVE-2026-24164

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

PUBLISHED
Vendor
NVIDIA
Product
BioNeMo Framework
Provider severity
HIGH
Conflicts
0

CVE-2026-24163

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
HIGH
Conflicts
0

CVE-2026-24162

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

PUBLISHED
Vendor
NVIDIA
Product
Merlin Transformers4Rec
Provider severity
HIGH
Conflicts
0

CVE-2026-24160

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

PUBLISHED
Vendor
NVIDIA
Product
TensorRT-LLM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2416

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
cyberhobo
Product
Geo Mashup
Provider severity
HIGH
Conflicts
0