Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Nvidia Geforce NOW18/9/202017/6/2026
NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensitive information as part of a URL, which may lead to information disclosure.
ModificadaMedia (4.7)0.27%—Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+125/6/202017/6/2026
NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.
ModificadaMedia (5.5)0.35%—Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware25/6/202017/6/2026
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service.
ModificadaAlta (7.8)0.35%—Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce ExperienceNvidia NVS Firmware+125/6/202017/6/2026
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.
ModificadaAlta (7.8)0.47%—Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+125/6/202017/6/2026
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
ModificadaAlta (7.8)0.32%—Nvidia Quadro FirmwareNvidia Geforce FirmwareNvidia Tesla FirmwareNvidia NVS Firmware24/6/202017/6/2026
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.
ModificadaAlta (7.8)0.37%—Nvidia Quadro FirmwareNvidia Geforce ExperienceNvidia Tesla Firmware11/3/202017/6/2026
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure.
ModificadaAlta (7.8)0.32%—Nvidia Quadro FirmwareNvidia Geforce ExperienceNvidia Tesla Firmware5/3/202017/6/2026
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.
ModificadaAlta (7.8)0.38%—Nvidia Geforce Experience24/12/201917/6/2026
NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.
ModificadaMedia (6.5)0.92%—Nvidia Geforce ExperienceNvidia GPU Driver12/11/201917/6/2026
NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can incorrectly load Windows system DLLs without validating the path or signature (also known as a…
ModificadaAlta (7.8)0.55%—Nvidia Geforce Experience9/11/201917/6/2026
NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to…
ModificadaAlta (7.8)0.35%—Nvidia Geforce Experience9/11/201917/6/2026
NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a user with local system access can craft input that may allow malicious files to be downloaded and saved. This behavior may lead to code execution, denial of service, or information disclosure.
ModificadaAlta (7.8)0.93%—Nvidia Geforce Experience31/5/201917/6/2026
NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated. Such an attack may lead to code execution, denial of service or information disclosure.
ModificadaMedia (6.7)0.52%—Nvidia GPU Display DriverNvidia Geforce Experience10/5/201917/6/2026
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.
ModificadaMedia (6.5)1.4%—Canonical Ubuntu LinuxNvidia Geforce GTX 745 FirmwareNvidia Geforce GTX 750 FirmwareNvidia Geforce GTX 750 TI Firmware+131/4/201917/6/2026
A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability.…
ModificadaAlta (7)1.2%—Nvidia Geforce Experience28/3/201917/6/2026
NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.
ModificadaMedia (5.5)0.31%—Nvidia Geforce Experience27/11/201817/6/2026
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
ModificadaAlta (7.8)0.31%—Nvidia Geforce Experience27/11/201817/6/2026
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who initiates a browser session may obtain escalation of privileges on the browser.
ModificadaAlta (7.8)0.31%—Nvidia Geforce Experience27/11/201817/6/2026
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has access to a local user account can plant a malicious dynamic link library (DLL) during application installation, which may lead to escalation of privileges.
ModificadaBaja (2.5)0.24%—Nvidia Geforce Experience2/10/201817/6/2026
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.
ModificadaAlta (7)0.29%—Nvidia Geforce Experience2/10/201817/6/2026
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permissions on a file, which may to code execution, denial of service, or escalation of privileges by users with system access.
ModificadaBaja (2.5)0.24%—Nvidia Geforce Experience31/8/201817/6/2026
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possible.
ModificadaMedia (4.7)0.25%—Nvidia Geforce Experience31/8/201817/6/2026
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation where an attacker who has system access can potentially conduct a Man-in-the-Middle (MitM) attack to obtain sensitive information.
ModificadaAlta (7)0.28%—Nvidia Geforce Experience31/8/201817/6/2026
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled where improper access control may lead to a denial of service, escalation of privileges, or both.
ModificadaAlta (7.8)0.29%—Nvidia Geforce Experience16/10/201717/6/2026
In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.
Orbitaley — Vulnerabilidades