cbcvebase.
CVE-2025-33220
published 2026-01-28

CVE-2025-33220: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.4th percentile
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

Affected

11 ranges
VendorProductVersion rangeFixed in
nvidiageforce
nvidiageforce
nvidiageforce
nvidiageforce
nvidiatesla
nvidiatesla
nvidiatesla
nvidiatesla
nvidiavirtual_gpu_manager
nvidiavirtual_gpu_manager
nvidiavirtual_gpu_manager

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.