Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.9) | 0.80% | — | Nvidia Openshell | 25/8/2026 | 1/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (8.5) | 0.63% | — | Nvidia Openshell | 25/8/2026 | 1/9/2026 | NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Alta (8.8) | 2.6% | — | Nvidia Openshell | 25/8/2026 | 2/9/2026 | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Media (5.5) | 0.17% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Media (6.1) | 0.15% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Media (6.8) | 2.4% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |
| Analizada | Media (5.2) | 0.17% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Crítica (9.8) | 0.51% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges. | |
| Analizada | Crítica (9.9) | 0.86% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. | |
| Analizada | Alta (7.8) | 0.22% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Crítica (9.8) | 0.41% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service. | |
| Analizada | Alta (8.2) | 0.20% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6) | 0.18% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi. | |
| Analizada | Alta (8.2) | 0.15% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Alta (8.2) | 0.15% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6) | 0.13% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure. | |
| En análisis | Alta (8.8) | 0.32% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges. | |
| En análisis | Alta (8) | 0.37% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. | |
| En análisis | Media (6.8) | 0.97% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure. | |
| En análisis | Media (6.8) | 0.28% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. | |
| En análisis | Media (5.1) | 0.13% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges. | |
| Analizada | Media (5.5) | 0.18% | 💥 PoC | Nvidia Triton Inference Server | 18/8/2026 | 1/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution. |