Gigabyte's vulnerability profile spans a modestly represented but strategically important portfolio of consumer and enthusiast computing products, including graphics drivers, system utilities, and motherboard firmware that reach deeply into gaming and high-performance builds. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation, concentrated in widely installed software such as AORUS Graphics Engine, App Center, and OC Guru II, with recurring weaknesses in input validation, unsafe deserialization, and exposed dangerous functions that are characteristic of system-level software running with elevated privileges. Defenders should prioritize patching Gigabyte drivers and firmware utilities across their installed base, particularly systems with direct internet exposure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gigabyte over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19323CRITICAL The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionali | Dec 21, 2018 | 9.8 | 73 | YES | NO |
CVE-2018-19321HIGH The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose | Dec 21, 2018 | 7.8 | 65 | YES | NO |
CVE-2018-19322HIGH The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose | Dec 21, 2018 | 7.8 | 64 | YES | NO |
CVE-2018-19320HIGH The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcp | Dec 21, 2018 | 7.8 | 64 | YES | NO |
CVE-2026-4415CRITICAL Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary f | Mar 30, 2026 | 9.8 | 36 | NO | NO |
CVE-2017-3198CRITICAL GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker c | Jul 9, 2018 | 9.8 | 30 | NO | NO |
CVE-2010-1518HIGH Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory c | Aug 2, 2010 | 10.0 | 29 | NO | NO |
CVE-2010-1517HIGH The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving th | Aug 2, 2010 | 10.0 | 29 | NO | NO |
CVE-2017-3197CRITICAL GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a resu | Jul 9, 2018 | 9.8 | 28 | NO | NO |
CVE-2026-4416HIGH The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to | Mar 30, 2026 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gigabyte.
Media articles that mention a CVE ID that affects a product developed by Gigabyte — matched by CVE ID, not by vendor name.