Nvidia Nemo vulnerabilities
31 known vulnerabilities affecting nvidia/nemo.
Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH22MEDIUM1
Vulnerabilities
Page 1 of 2
CVE-2026-24159CRITICALCVSS 9.8fixed in 2.6.22026-03-24
CVE-2026-24159 [HIGH] CWE-502 CVE-2026-24159: NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A
NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
nvd
CVE-2026-24157CRITICALCVSS 9.8fixed in 2.6.22026-03-24
CVE-2026-24157 [HIGH] CWE-502 CVE-2026-24157: NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause r
NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
nvd
CVE-2025-33245HIGHCVSS 8.8fixed in 2.6.12026-02-18
CVE-2025-33245 [HIGH] CWE-502 CVE-2025-33245: NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code executio
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33250HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33250 [HIGH] CWE-94 CVE-2025-33250: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution.
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
nvd
CVE-2025-33251HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33251 [HIGH] CWE-94 CVE-2025-33251: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution.
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
nvd
CVE-2025-33249HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33249 [HIGH] CWE-77 CVE-2025-33249: NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, wh
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33241HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33241 [HIGH] CWE-502 CVE-2025-33241: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution b
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33243HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33243 [HIGH] CWE-502 CVE-2025-33243: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution i
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33252HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33252 [HIGH] CWE-502 CVE-2025-33252: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution.
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
nvd
CVE-2025-33246HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33246 [HIGH] CWE-77 CVE-2025-33246: NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
nvd
CVE-2025-33236HIGHCVSS 7.8fixed in 2.6.12026-02-18
CVE-2025-33236 [HIGH] CWE-94 CVE-2025-33236: NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cau
NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33253HIGHCVSS 7.3fixed in 2.6.12026-02-18
CVE-2025-33253 [HIGH] CWE-502 CVE-2025-33253: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution b
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
nvd
CVE-2025-33226HIGHCVSS 7.8fixed in 2.5.32025-12-16
CVE-2025-33226 [HIGH] CWE-502 CVE-2025-33226: NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an
NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33212HIGHCVSS 7.8fixed in 2.5.32025-12-16
CVE-2025-33212 [HIGH] CWE-502 CVE-2025-33212: NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to expl
NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.
nvd
CVE-2025-33204HIGHCVSS 7.8fixed in 2.5.12025-11-25
CVE-2025-33204 [HIGH] CWE-94 CVE-2025-33204: NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, wher
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-33205HIGHCVSS 7.3fixed in 2.5.12025-11-25
CVE-2025-33205 [HIGH] CWE-829 CVE-2025-33205: NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cau
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution.
nvd
CVE-2025-33178HIGHCVSS 7.8fixed in 2.5.02025-11-11
CVE-2025-33178 [HIGH] CWE-94 CVE-2025-33178: NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component wher
NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to Code execution, Escalation of privileges, Information disclosure, and Data tampering.
nvd
CVE-2025-23361HIGHCVSS 7.8fixed in 2.5.02025-11-11
CVE-2025-23361 [HIGH] CWE-94 CVE-2025-23361: NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input
NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control of code generation. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-23314HIGHCVSS 7.8fixed in 2.4.02025-08-26
CVE-2025-23314 [HIGH] CWE-94 CVE-2025-23314: NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicio
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2025-23312HIGHCVSS 7.8fixed in 2.4.02025-08-26
CVE-2025-23312 [HIGH] CWE-94 CVE-2025-23312: NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
1 / 2Next →