Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gigabyte

First CVE: Nov 23, 2004Active for: 22 yearsTotal CVEs: 12
53.9
VTI Score
TOP TARGET

Gigabyte's vulnerability profile spans a modestly represented but strategically important portfolio of consumer and enthusiast computing products, including graphics drivers, system utilities, and motherboard firmware that reach deeply into gaming and high-performance builds. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation, concentrated in widely installed software such as AORUS Graphics Engine, App Center, and OC Guru II, with recurring weaknesses in input validation, unsafe deserialization, and exposed dangerous functions that are characteristic of system-level software running with elevated privileges. Defenders should prioritize patching Gigabyte drivers and firmware utilities across their installed base, particularly systems with direct internet exposure; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
33.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Gigabyte over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2004
21 years ago
Most Recent CVE
Mar 30, 2026
116 days ago

Products(13 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-19323CRITICAL
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionali
Dec 21, 20189.873YESNO
CVE-2018-19321HIGH
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose
Dec 21, 20187.865YESNO
CVE-2018-19322HIGH
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose
Dec 21, 20187.864YESNO
CVE-2018-19320HIGH
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcp
Dec 21, 20187.864YESNO
CVE-2026-4415CRITICAL
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary f
Mar 30, 20269.836NONO
CVE-2017-3198CRITICAL
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker c
Jul 9, 20189.830NONO
CVE-2010-1518HIGH
Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory c
Aug 2, 201010.029NONO
CVE-2010-1517HIGH
The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving th
Aug 2, 201010.029NONO
CVE-2017-3197CRITICAL
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a resu
Jul 9, 20189.828NONO
CVE-2026-4416HIGH
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to
Mar 30, 20267.827NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local4 (33.3%)
Network5 (41.7%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High0 (0.0%)
Unknown3 (25.0%)
User Interaction
None9 (75.0%)
Unknown3 (25.0%)
Required0 (0.0%)
Privileges Required
Low4 (33.3%)
High1 (8.3%)
None4 (33.3%)
Unknown3 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
4 CVEs
33.3% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gigabyte.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gigabyte — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gigabyte's Products

View all 3 CNAs →

Top CWEs