VYPR

product-security

by Nvidia

CVEs (43)

  • CVE-2026-65093CriAug 25, 2026
    risk 0.64cvss 9.9epss 0.01

    NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24170HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and…

  • CVE-2026-24260HigJul 1, 2026
    risk 0.55cvss 8.5epss 0.00

    NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.

  • CVE-2026-47623HigAug 4, 2026
    risk 0.53cvss 8.2epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-24253HigAug 4, 2026
    risk 0.53cvss 8.2epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-24169HigAug 25, 2026
    risk 0.52cvss 8.0epss 0.01

    NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of…

  • CVE-2026-65089HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

  • CVE-2026-47625HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

  • CVE-2026-47629HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.

  • CVE-2026-47618HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47617HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47615HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47613HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47612HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-24255HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might…

  • CVE-2026-61779HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61778HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61777HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61776HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61773HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Page 1 of 3