Slurm

Vendor:

First CVE: Jan 5, 2017 · Active for 9 years

25
Total CVEs
More Total CVEs than 96% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Slurm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 5, 2017
9 years ago
Most Recent CVE
Jan 16, 2026
193 days ago

CVE Severity & Scoring

Slurm25 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local3 (12.0%)
Network22 (88.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (72.0%)
High7 (28.0%)
Unknown0 (0.0%)
User Interaction
None25 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (44.0%)
High0 (0.0%)
None14 (56.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
May 5, 20229.832NONO
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
Jul 11, 20199.832NONO
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
Mar 15, 20189.831NONO
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
Nov 27, 20209.830NONO
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
May 5, 20228.829NONO
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
May 5, 20228.828NONO
SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads t
May 13, 20218.828NONO
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A rac
May 21, 20208.127NONO
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root duri
Nov 1, 20177.826NONO
An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.
Dec 14, 20239.825NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Slurm

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
23.1158.70.9%00
19.05.019.82.7%00
17.11.6.115.31.7%00
17.11.5.115.31.7%00
17.11.4.115.31.7%00
17.11.3.215.31.7%00
17.11.3.115.31.7%00
17.11.2.115.31.7%00
17.11.1.215.31.7%00
17.11.1.115.31.7%00
17.11.0.115.31.7%00
17.11.0.027.51.9%00
17.11.017.80.6%00
17.02.018.12.5%00
16.05.618.12.5%00
16.05.518.12.5%00
16.05.418.12.5%00
16.05.318.12.5%00
16.05.218.12.5%00
16.05.118.12.5%00