358 vulnerabilidades · Cloud Orden: CVSS EPSS Año ID
CVE-2024-0091
GPU display driver, vGPU software, and Cloud Gaming Web Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-822 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVE-2015-5119
🔥 KEV Software Genérico Cloud Windows
7.8
HIGH
EPSS
93.2%
2015 5 PoCs

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVE-2023-0182
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service, information disclosure, and data tampering.

CVE-2024-0071
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-125 2 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0107
GPU Display Driver, vGPU Software, Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.3%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0077
vGPU driver, Cloud Gaming driver Cloud
7.8
HIGH
EPSS
0.0%
2024 CWE-285 1 PoC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources for which the guest OS is not authorized. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0118
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2025-63261
Software Genérico Cloud
7.8
HIGH
EPSS
0.1%
2025 1 PoC

AWStats 8.0 is vulnerable to Command Injection via the open function

CVE-2022-34672
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-284 1 PoC

NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or executing commands.

CVE-2024-0073
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2024 CWE-250 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer when the driver is performing an operation at a privilege level that is higher than the minimum level required. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0119
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2025-15561
WorkTime (on-prem/cloud) Cloud
7.8
HIGH
EPSS
0.0%
2025 CWE-269 1 PoC

An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named  WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The executable will then be run by the WorkTime monitoring daemon.

CVE-2024-0084
vGPU software and Cloud Gaming Cloud
7.8
HIGH
EPSS
0.2%
2024 CWE-250 1 PoC

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.

CVE-2024-0117
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0089
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-665 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.

CVE-2025-6087
Software Genérico Web Cloud
7.8
HIGH
EPSS
0.5%
2025 CWE-918 4 PoCs

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed attackers to load remote resources from arbitrary hosts under the victim site’s domain for any site deployed using the Cloudflare adapter for Open Next.  For example: https://victim-site.com/_next/image?url=https://attacker.com In this example, attacker-controlled conten

CVE-2024-0121
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2021-40867
Software Genérico Web Cloud
7.8
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who uses the same source IP address as an admin in the process of logging in (e.g., behind the same NAT device, or already in possession of a foothold on an admin's machine). This occurs because the multi-step HTTP authentication process is effectively tied only to the source IP address. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1

CVE-2015-5123
🔥 KEV Software Genérico Cloud Windows
7.8
HIGH
EPSS
41.0%
2015 2 PoCs

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.