Schedmd develops SLURM, a workload manager and resource scheduler widely deployed across high-performance computing clusters and research environments, where its privileged role in job orchestration creates a substantial attack surface despite the vendor's narrow product scope. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across weakness classes including buffer overflows, SQL injection, race conditions, and synchronization flaws that are characteristic of large C-based system software handling untrusted workload submissions. The exposure reflects SLURM's trusted position in HPC infrastructure: a single flaw can enable privilege escalation or resource-allocation manipulation with consequences across an entire computing cluster. Defenders should prioritize SLURM patching in research and scientific computing environments and monitor the vendor's security advisories closely; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schedmd over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29502CRITICAL SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. | May 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-12838CRITICAL SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. | Jul 11, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-7033CRITICAL SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD. | Mar 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-27745CRITICAL Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin. | Nov 27, 2020 | 9.8 | 30 | NO | NO |
CVE-2022-29501HIGH SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution. | May 5, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-29500HIGH SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure. | May 5, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-31215HIGH SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads t | May 13, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-12693HIGH Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A rac | May 21, 2020 | 8.1 | 27 | NO | NO |
CVE-2017-15566HIGH Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root duri | Nov 1, 2017 | 7.8 | 26 | NO | NO |
CVE-2023-49934CRITICAL An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1. | Dec 14, 2023 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schedmd.
Media articles that mention a CVE ID that affects a product developed by Schedmd — matched by CVE ID, not by vendor name.