Ni
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Ni product.
RSS Feeds for Ni security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Ni products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Ni Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 8 vulnerabilities in Ni with an average score of 7.8 out of ten. Last year, in 2025 Ni had 28 security vulnerabilities published. Right now, Ni is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.09
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 8 | 7.79 |
| 2025 | 28 | 7.88 |
| 2024 | 16 | 8.01 |
| 2023 | 2 | 7.15 |
| 2022 | 3 | 7.23 |
| 2021 | 1 | 7.80 |
It may take a day or so for new Ni vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Ni Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-8036 | Jun 02, 2026 |
NI-PAL (26.3.0) Improper Input Validation: Privilege Escalation on Windows/LinuxImproper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux. |
|
| CVE-2026-8035 | Jun 02, 2026 |
NI-PAL 26.3.0 Kernel: NULL Pointer Crash via Improper Input ValidationImproper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux. |
|
| CVE-2026-9051 | May 29, 2026 |
NI SystemLink Enterprise Dashboard Auth BypassThere is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure. Successful exploitation requires an attacker to send a specially crafted HTTP request. This vulnerability affects NI SystemLink Enterprise 2026-04 and prior versions. |
|
| CVE-2026-32864 | Apr 07, 2026 |
NI LabVIEW 2026 Q1 (26.1.0) Memory Corruption in mgcore_SH_25_3!aligned_freeThere is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions. |
|
| CVE-2026-32863 | Apr 07, 2026 |
NI LabVIEW 26.1.0 OOB Read in sentry_transaction_context_set_operationThere is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions. |
|
| CVE-2026-32862 | Apr 07, 2026 |
NI LabVIEW Memory Corruption in ResFileFactory (before 26.1)There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions. |
|
| CVE-2026-32861 | Apr 07, 2026 |
Out-of-bounds Write in NI LabVIEW 26.1.0 LVCLASS LoaderThere is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvclass file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions. |
|
| CVE-2026-32860 | Apr 07, 2026 |
NI LabVIEW 2026 Q1 Memory corruption via LVLIB (CVE-2026-32860)There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .lvlib file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions. |
|
| CVE-2025-64469 | Dec 18, 2025 |
NI LabVIEW <25.3: Stack overflow in LVResFile::FindRsrcListEntry()There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64468 | Dec 18, 2025 |
NI LabVIEW 25.3 UAF in sentry!* Info leak via crafted VIThere is a use-after-free vulnerability in sentry!sentry_span_set_data() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions |
|
| CVE-2025-64467 | Dec 18, 2025 |
NI LabVIEW OOB Read in LVResFile::FindRsrcListEntry() (pre-25.3)There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64466 | Dec 18, 2025 |
NI LabVIEW OOB Read in lvre!ExecPostedProcRecPost() before 25.3There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64465 | Dec 18, 2025 |
OOB Read in NI LabVIEW 25.3 via lvre!DataSizeTDR(): Info Disclosure & Code ExecThere is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64464 | Dec 18, 2025 |
OOB Read in NI LabVIEW lvre!VisaWriteFromFile() Info Disclosure/CODE EXEC(25.3)There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64463 | Dec 18, 2025 |
NI LabVIEW 25.3 & prior: OOB read in LVResource::DetachResource()There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64462 | Dec 18, 2025 |
NI LabVIEW 25.3 OOB Read in LVResFile::RGetMemFileHandle() - Info disclosureThere is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-64461 | Dec 18, 2025 |
NI LabVIEW OOBV in mgocre_SH_25_3!RevBL() pre-25.3There is an out of bounds write vulnerability in NI LabVIEW in mgocre_SH_25_3!RevBL() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions. |
|
| CVE-2025-12097 | Dec 04, 2025 |
NI SWS Path Traversal Exposes FilesThere is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files. This vulnerability existed in the NI System Web Server 2012 and prior versions. It was fixed in 2013. |
|
| CVE-2025-6034 | Sep 30, 2025 |
NI Circuit Design Suite 14.3.1 Memory Corruption via SymbolEditor DefaultFontOptions()There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.1 and prior versions. |
|
| CVE-2025-6033 | Sep 30, 2025 |
Buffer Overrun in XML_Serialize() SymbolEditor (NI Circuit Design Suite <=14.3.1)There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.1 and prior versions. |
|
| CVE-2025-7361 | Jul 29, 2025 |
NI LabVIEW 32-bit RCE via CIN Node Code InjectionA code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node. This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions. LabVIEW 64-bit versions do not support CIN nodes and are not affected. |
|
| CVE-2025-7848 | Jul 29, 2025 |
NI LabVIEW RCE via lvpict.cpp memory corruptionA memory corruption vulnerability due to improper input validation in lvpict.cpp exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-7849 | Jul 29, 2025 |
NI LabVIEW RCE via NULL VILinkObj Mem CorruptionA memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-2634 | Jul 23, 2025 |
Out-of-Bounds Read in NI LabVIEW fontmgr Enables RCEOut of bounds read vulnerability due to improper bounds checking in NI LabVIEW in fontmgr may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-2633 | Jul 23, 2025 |
NI LabVIEW OOB Read RCE via lvre!UDecStrToNum in VIOut of bounds read vulnerability due to improper bounds checking in NI LabVIEW in lvre!UDecStrToNum that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-30420 | May 15, 2025 |
Memory Corruption OOB Read in NI Circuit Design Suite 14.3.0 SymbolEditorThere is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions. |
|
| CVE-2025-30419 | May 15, 2025 |
NI Circuit Design Suite 14.3.0 Memory Corruption in GetSymbolBorderRectSize()There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions. |
|
| CVE-2025-30418 | May 15, 2025 |
NI Circuit Design Suite 14.3.0 and prior: MemCor in CheckPins (SymbolEditor)There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions. |
|
| CVE-2025-30417 | May 15, 2025 |
NI Circuit Design Suite <14.3.0: OOB Write in DecodeBase64() via SymbolEditorThere is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions. |
|
| CVE-2025-30421 | May 15, 2025 |
NI Circuit Design Suite <14.3.0: Stack Buffer Overflow in SymbolEditor XML_SerializeThere is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .sym file. This vulnerability affects NI Circuit Design Suite 14.3.0 and prior versions. |
|
| CVE-2025-2632 | Apr 09, 2025 |
NI LabVIEW OOB Write in CPU Cache Parsing - CVE-2025-2632Out of bounds write vulnerability due to improper bounds checking in NI LabVIEW reading CPU info from cache that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-2631 | Apr 09, 2025 |
NI LabVIEW OOB Write in InitCPUInformation() leading to code execOut of bounds write vulnerability due to improper bounds checking in NI LabVIEW in InitCPUInformation() that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-2630 | Apr 09, 2025 |
NI LabVIEW DLL Hijacking via Uncontrolled Path – Arbitrary ExecThere is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-2629 | Apr 09, 2025 |
NI LabVIEW DLL Hijacking – Arbitrary Code Execution via Uncontrolled Search PathThere is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions. |
|
| CVE-2025-2450 | Mar 18, 2025 |
NI Vision Builder AI: RCE via VBAI File ProcessingNI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of VBAI files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22833. |
|
| CVE-2025-2449 | Mar 18, 2025 |
NI FlexLogger usiReg URI Fil Parsing DIR-Trav RCENI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of URI files by the usiReg component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21805. |
|
| CVE-2024-10494 | Dec 10, 2024 |
NI LabVIEW HeapObjMapImpl Out-of-Bounds Read VulnerabilityAn out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions. |
|
| CVE-2024-10495 | Dec 10, 2024 |
NI LabVIEW Font Table Out-of-Bounds Read VulnerabilityAn out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions. |
|
| CVE-2024-10496 | Dec 10, 2024 |
NI LabVIEW: Out-of-Bounds Read in BuildFontMap FunctionAn out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions. |
|
| CVE-2024-4080 | Jul 23, 2024 |
LabVIEW Memory Corruption in tdcore.dll Enables Remote Code ExecA memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions. |
|
| CVE-2024-4079 | Jul 23, 2024 |
LabVIEW OOB Read/Exec via Crafted VIAn out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions. |
|
| CVE-2024-4081 | Jul 23, 2024 |
NI LabVIEW 2024 Q1 Memory Corrupt in VI Enables Info Disclosure & ExecA memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects NI LabVIEW 2024 Q1 and prior versions. |
|
| CVE-2024-6805 | Jul 22, 2024 |
NI VeriStand: Auth Bypass in File Transfer RCE/Info DisclosureThe NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions. |
|
| CVE-2024-6806 | Jul 22, 2024 |
NI VeriStand RCE via Missing Auth on Project ResourcesThe NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions. |
|
| CVE-2024-6794 | Jul 22, 2024 |
NI VeriStand Remote Code Exec via Deserialization in Waveform Streaming ServerA deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions. |
|
| CVE-2024-6793 | Jul 22, 2024 |
NI VeriStand DataLogging Server Deserialization RCE VulnerabilityA deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions. |
|
| CVE-2024-6791 | Jul 22, 2024 |
NI VeriStand path traversal via .vsmodel file enabling RCEA directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .vsmodel file. This vulnerability affects VeriStand 2024 Q2 and prior versions. |
|
| CVE-2024-6121 | Jul 22, 2024 |
NI SystemLink Server Outdated Redis Enables Multiple Exploits (CVE-2024-6121)An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service. |
|
| CVE-2024-6122 | Jul 22, 2024 |
NI SystemLink Server KeyValueDatabase Directory Permission Flaw (CVE-2024-6122)An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service. |
|
| CVE-2024-6638 | Jul 22, 2024 |
LabVIEW TDMS Integer Overflow Infinite Loop VulnerabilityAn integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1 and prior versions. |
|