Known vulnerabilities in NVIDIA App (formerly GeForce Experience)

Vendor: nVidia
Software CPE: cpe:2.3:a:nvidia:geforce_experience:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting NVIDIA App (formerly GeForce Experience) NVIDIA App (formerly GeForce Experience) is affected by 16 known vulnerabilities: 2 medium, 14 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107878 - Use of Hard-coded, Security-relevant Constants
CVE-2025-23253
CWE-547 Low
No
No
11.0.2.341 23.04.2025 SB2025042333
#VU59082 - Improper Access Control
CVE-2021-23175
CWE-284 Low
No
No
3.24.0.126 22.12.2021 SB2021122201
#VU54380 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-1073
CWE-451 Medium
No
No
3.23.0.74 25.06.2021 SB2021062501
#VU27858 - Memory corruption
CVE-2020-1079
CWE-119 Low
No
No
3.22.0.32 12.05.2020 SB2020051272
SB2021041921
#VU24381 - Missing Authorization
CVE-2019-5702
CWE-862 Low
No
No
3.20.2 17.01.2020 SB2019122404
#VU16001 - Exposure of sensitive information to an unauthorized actor
CVE‑2018‑6266
CWE-200 Low
No
No
3.16 21.11.2018 SB2018112116
#VU16000 - Permissions, Privileges, and Access Controls
CVE‑2018‑6265
CWE-264 Low
No
No
3.16 21.11.2018 SB2018112116
#VU15999 - Uncontrolled Search Path Element
CVE‑2018‑6263
CWE-427 Low
No
No
3.16 21.11.2018 SB2018112116
#VU15339 - Permissions, Privileges, and Access Controls
CVE‑2018‑6262
CWE-264 Low
No
No
3.15 12.10.2018 SB2018101208
#VU15338 - Permissions, Privileges, and Access Controls
CVE‑2018‑6261
CWE-264 Low
No
No
3.15 12.10.2018 SB2018101208
#VU31196 - Incorrect Default Permissions
CVE-2018-6261
CWE-276 Low
No
No
3.15 02.10.2018 SB2018100211
#VU31197 - Exposure of sensitive information to an unauthorized actor
CVE-2018-6262
CWE-200 Low
No
No
3.15 02.10.2018 SB2018100211
#VU14599 - Exposure of sensitive information to an unauthorized actor
CVE-2018-6259
CWE-200 Low
No
No
3.14.1 03.09.2018 SB2018090310
#VU14598 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2018-6258
CWE-300 Low
No
No
3.14.1 03.09.2018 SB2018090310
#VU14597 - Improper Access Control
CVE-2018-6257
CWE-284 Low
No
No
3.14.1 03.09.2018 SB2018090310
#VU1128 - Stack-based buffer overflow
CVE-2016-8812
CWE-121 Medium
Available
No
- 01.11.2016 SB2016110128