Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-3912 — TIBCO ActiveMatrix BusinessWorks Injection Vulnerability

Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessi…

Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.5 MEDIUM
CVE-2026-3889 — Spoofing issue in Thunderbird

Spoofing issue in Thunderbird. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

thunderbird | Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.5 MEDIUM
CVE-2026-33215 — NATS is vulnerable to MQTT hijacking via Client ID

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and M…

Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-24159 — NVIDIA NeMo Framework Remote Code Execution Vulnerability

NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, in…

nemo | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.5 HIGH
CVE-2026-24158 — NVIDIA Triton Inference Server HTTP Compressed Payload Denial of Service

NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker may cause a denial of service by providing a large compressed payload. A successful exploit of this vuln…

triton_inference_server | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-24157 — NVIDIA NeMo Framework Remote Code Execution Vulnerability

NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, esca…

nemo | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-24152 — NVIDIA Megatron-LM Remote Code Execution Vulnerability

NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerabilit…

megatron-lm | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-24151 — NVIDIA Megatron-LM Remote Code Execution

NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously crafted input. A successful exploit of this vulnerability may …

megatron-lm | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-24150 — NVIDIA Megatron-LM Checkpoint Loading Remote Code Execution (RCE)

NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerabilit…

megatron-lm | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-24141 — NVIDIA Model Optimizer ONNX Deserialization Code Execution Vulnerability

NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A …

| Misconfiguration
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.3 MEDIUM
CVE-2026-21790 — HCL Traveler is susceptible to a weak default HTTP header validation vulnerability

HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.

Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.5 HIGH
CVE-2025-33254 — NVIDIA Triton Inference Server State Corruption Denial of Service Vulnerability

NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A successful exploit of this vulnerability may lead to a denial of service.

triton_inference_server | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2025-33248 — NVIDIA Megatron-LM Remote Code Execution Vulnerability

NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vu…

megatron-lm | Misconfiguration
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2025-33247 — NVIDIA Megatron LM Remote Code Execution Vulnerability

NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, es…

megatron-lm | Misconfiguration
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
9.0 CRITICAL
CVE-2025-33244 — NVIDIA APEX Deserialization Vulnerability

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlie…

apex | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
5.9 MEDIUM
CVE-2025-33242 — NVIDIA B300 MCU CX8 MCU Registry Modification Vulnerability

NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registries, causing a bad state. A successful exploit of this vulnerability might lead…

Remote | Misconfiguration
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.5 HIGH
CVE-2025-33238 — NVIDIA Triton Inference Server Sagemaker HTTP Server Denial of Service Vulnerability

NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. A successful exploit of this vulnerability may lead to denial of service.

triton_inference_server | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.8 MEDIUM
CVE-2025-33216 — NVIDIA SNAP-4 Container Buffer Overflow Denial of Service

NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an incorrect calculation of buffer size by sending crafted configurations. A succes…

| Misconfiguration
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.8 MEDIUM
CVE-2025-33215 — NVIDIA SNAP-4 VIRTIO-BLK Pointer Offset Vulnerability

NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit …

| Memory Corruption
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
8.8 HIGH
CVE-2026-33511 — pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by a…

pyload-ng | Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
Showing 20 of 6033 Results