Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Schedmd

First CVE: Jan 5, 2017Active for: 10 yearsTotal CVEs: 25
44.8
VTI Score
High

Schedmd develops SLURM, a workload manager and resource scheduler widely deployed across high-performance computing clusters and research environments, where its privileged role in job orchestration creates a substantial attack surface despite the vendor's narrow product scope. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across weakness classes including buffer overflows, SQL injection, race conditions, and synchronization flaws that are characteristic of large C-based system software handling untrusted workload submissions. The exposure reflects SLURM's trusted position in HPC infrastructure: a single flaw can enable privilege escalation or resource-allocation manipulation with consequences across an entire computing cluster. Defenders should prioritize SLURM patching in research and scientific computing environments and monitor the vendor's security advisories closely; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Schedmd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 5, 2017
9 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-29502CRITICAL
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
May 5, 20229.832NONO
CVE-2019-12838CRITICAL
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
Jul 11, 20199.832NONO
CVE-2018-7033CRITICAL
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
Mar 15, 20189.831NONO
CVE-2020-27745CRITICAL
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
Nov 27, 20209.830NONO
CVE-2022-29501HIGH
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
May 5, 20228.829NONO
CVE-2022-29500HIGH
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
May 5, 20228.828NONO
CVE-2021-31215HIGH
SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads t
May 13, 20218.828NONO
CVE-2020-12693HIGH
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A rac
May 21, 20208.127NONO
CVE-2017-15566HIGH
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root duri
Nov 1, 20177.826NONO
CVE-2023-49934CRITICAL
An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.
Dec 14, 20239.825NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
20%
48%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (12.0%)
Network22 (88.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (72.0%)
High7 (28.0%)
Unknown0 (0.0%)
User Interaction
None25 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (44.0%)
High0 (0.0%)
None14 (56.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Schedmd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Schedmd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Schedmd's Products

View all 1 CNAs →

Top CWEs