« Back to list

Nvidia

Nvidia Nemo: vulnerabilities and CVEs

Nvidia Nemo has 34 published vulnerabilities, 21 of them in the last 12 months. 8 are rated critical and 0 are listed by CISA as actively exploited.

CVEs34
Last 12 months21
Critical8
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-24252High (7.8)1.5%—Jul 27, 2026
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and…
CVE-2026-24228High (7.8)0.16%—Jun 16, 2026
NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges,…
CVE-2026-24155High (7.8)0.19%—Jun 16, 2026
NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data…
CVE-2026-24159Critical (9.8)0.64%—Mar 24, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure…
CVE-2026-24157Critical (9.8)0.65%—Mar 24, 2026
NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of…
CVE-2025-33253High (7.3)0.19%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code…
CVE-2025-33252High (7.8)0.21%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and…
CVE-2025-33251High (7.8)0.23%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and…
CVE-2025-33250High (7.8)0.23%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and…
CVE-2025-33249High (7.8)0.18%—Feb 18, 2026
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability…
CVE-2025-33246High (7.8)0.95%—Feb 18, 2026
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit…
CVE-2025-33245High (8.8)0.54%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information…
CVE-2025-33243High (7.8)0.22%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of…
CVE-2025-33241High (7.8)0.22%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution,…
CVE-2025-33236High (7.8)0.18%—Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…
CVE-2025-33226High (7.8)0.22%—Dec 16, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation…
CVE-2025-33212High (7.8)0.19%—Dec 16, 2025
NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a maliciously crafted file. A successful exploit of this vulnerability…
CVE-2025-33205High (7.3)0.15%—Nov 25, 2025
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of…
CVE-2025-33204High (7.8)0.20%—Nov 25, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead…
CVE-2025-33178High (7.8)0.28%—Nov 11, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead…
CVE-2025-23361High (7.8)0.26%—Nov 11, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control of code generation. A successful exploit of this vulnerability may…
CVE-2025-23315High (7.8)0.25%—Aug 26, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this…
CVE-2025-23314High (7.8)0.25%—Aug 26, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might…
CVE-2025-23313High (7.8)0.25%—Aug 26, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might…
CVE-2025-23312High (7.8)0.25%—Aug 26, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code injection. A successful exploit of this vulnerability…
CVE-2025-23304Critical (9.8)1.1%—Aug 13, 2025
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit…
CVE-2025-23303Critical (9.8)0.57%—Aug 13, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code…
CVE-2025-23251Critical (9.8)0.69%—Apr 22, 2025
NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and…
CVE-2025-23250Critical (9.8)0.63%—Apr 22, 2025
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might…
CVE-2025-23249Critical (9.8)0.68%—Apr 22, 2025
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter21
  2. T1068 Exploitation for Privilege Escalation15
  3. T1203 Exploitation for Client Execution3
  4. T1190 Exploit Public-Facing Application2
  5. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Nvidia