CVE Tools

Nvflare

7 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Nvflare, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Nvflare CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nvflare CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-043
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical457%
  • High229%
  • Medium114%

Latest CVEs

The 7 most recently published vulnerabilities affecting Nvflare.

  1. CVE-2026-24204NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.6.5
  2. CVE-2026-24186NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerab...8.8
  3. CVE-2026-24178NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A su...9.8
  4. CVE-2022-34668NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Deni...9.8
  5. CVE-2022-31605NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may a...9.8
  6. CVE-2022-31604NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of ...9.8
  7. CVE-2022-21822NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavaila...7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store