Open vulnerability database
The stack is the attack surface.
Running GPUs means running six layers of software and firmware, and an attacker only needs one of them. This is an open, community-maintained record of the vulnerabilities that matter to anyone operating GPU infrastructure — GPU clouds, colocation datacenters, and enterprises with their own fleets. Every entry carries what an operator has to do about it, not just a CVSS score.
1,404 entries243 critical120 known exploited6 layers of the stack
The stack, top to bottom1,404 entries
criticalhighmediumlowSelect a layer to filter
Serving sits at the top. Firmware sits under everything, and reboots the slowest.
Showing 60 of 1,404 entries · 243 critical · 120 known exploited
10.0CritSupermicro BMC (IPMI cipher suite 0): Authentication bypass — arbitrary IPMI commands with any password when cipher suite 0 is enabled. Still…CVE-2013-4782Firmware, BMC & network fabric10.0CritDell iDRAC (IPMI 1.5 cipher 0): Remote authentication bypass via cipher suite 0CVE-2013-4783Firmware, BMC & network fabric10.0CritHPE iLO (IPMI cipher 0): IPMI authentication bypass via cipher suite 0 on the iLO BMCCVE-2013-4784Firmware, BMC & network fabric10.0CritHPE iLO4: Authentication bypass and remote code execution — the "29 A's" `Connection` header bugCVE-2017-12542Firmware, BMC & network fabric10.0CritSupermicro BMC virtual media (H11/H12/M11/X9/X10/X11): Virtual media service uses weak/absent encryption and authentication — credential capture and attaching an…CVE-2019-16649Firmware, BMC & network fabric10.0CritGitLab: Image files passed unvalidated to a file parser (ExifTool)CVE-2021-22205Control plane, storage & DevOpsKnown exploited10.0CritJupyter Notebook (untrusted notebooks): Untrusted notebook executes JavaScript in the user's session on openCVE-2021-32798AI/ML frameworks & serving10.0CritRedis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCVE-2022-0543Control plane, storage & DevOpsKnown exploited10.0CritArgo CD: Unauthenticated attacker forges JWTs and gains full Argo CD admin, which in a GitOps cluster means…CVE-2022-29165Container, Kubernetes & orchestration10.0CritEnvoy: OAuth filter does not validate access tokens, so authentication can be skipped entirelyCVE-2022-29226Container, Kubernetes & orchestration10.0CritGitLab: Unauthenticated path traversal reads arbitrary server files when an attachment sits under 5+ nested groupsCVE-2023-2825Control plane, storage & DevOps10.0CritDGX A100 BMC: Full BMC compromise (heap buffer overflow) — worst-case out-of-band takeoverCVE-2023-31029NVIDIA / GPU stack10.0CritMLflow: Absolute path traversal prior to 2.5.0CVE-2023-3765AI/ML frameworks & serving10.0CritTorchServe: Unauthenticated SSRFCVE-2023-43654AI/ML frameworks & servingShellTorch10.0CritGitLab: Password reset email deliverable to an unverified addressCVE-2023-7028Control plane, storage & DevOpsKnown exploited10.0CritConnectWise ScreenConnect: Auth bypass via alternate pathCVE-2024-1709Control plane, storage & DevOpsKnown exploited10.0CritBuildKit: "Leaky Vessels": RUN --mount empty-file removal can delete arbitrary host filesCVE-2024-23652Container, Kubernetes & orchestration10.0CritBentoML: Insecure deserializationCVE-2024-2912AI/ML frameworks & serving10.0CritPalo Alto PAN-OS: GlobalProtect arbitrary file creationCVE-2024-3400Control plane, storage & DevOpsKnown exploited10.0Critllama.cpp (RPC backend): Unsafe `data` pointer in `rpc_tensor`CVE-2024-42479AI/ML frameworks & serving10.0CritGitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCVE-2024-45409Control plane, storage & DevOps10.0CritGitea: Stored cross-site scripting in Gitea 1.22.0CVE-2024-6886Control plane, storage & DevOps10.0CritMLflow (`extract_archive_to_dir`): Path traversal in the dbconnect artifact cacheCVE-2025-15036AI/ML frameworks & serving10.0CritvLLM (Mooncake ZMQ/TCP): Unsafe deserialization exposed on all interfacesCVE-2025-32444AI/ML frameworks & serving10.0CritCommvault Command Center: Unauthenticated ZIP upload + path traversalCVE-2025-34028Control plane, storage & DevOpsKnown exploited10.0CritIvanti Sentry: OS command injectionCVE-2026-10520Control plane, storage & DevOpsKnown exploited10.0CritChromaDB: Pre-authentication code injectionCVE-2026-45829AI/ML frameworks & serving9.9CritMicrosoft Hyper-V: vmswitch fails to validate guest OID requests - guest reads arbitrary host kernel memory or crashes the hostCVE-2021-28476Kernel, userspace & hypervisor9.9CritRancher: Cluster owners, members and even base users retrieve plaintext credentials via the Kubernetes APICVE-2021-36782Container, Kubernetes & orchestration9.9CritRancher: Insufficiently protected credentials let project members read passwords and API tokensCVE-2021-36783Container, Kubernetes & orchestration9.9CritArgo CD: Improper access control allows a low-privileged user to escalate to Argo CD adminCVE-2022-24768Container, Kubernetes & orchestration9.9CritRancher: Cleartext credential storage lets managed-cluster users read credentialsCVE-2022-43757Container, Kubernetes & orchestration9.9CritRancher: Standard users manipulate Kubernetes secrets in the local (management) clusterCVE-2023-22647Container, Kubernetes & orchestration9.9CritRancher: Update-logic failure misconfigures Rancher's admission webhook, disabling the validation that enforces tenant…CVE-2023-22651Container, Kubernetes & orchestration9.9CritRKE / Rancher (k8s control plane): full-cluster-state configmap in kube-system readable by non-adminsCVE-2023-32191Control plane, storage & DevOps9.9CritArgo CD: Cluster secrets stored in the last-applied-configuration annotation are readable by anyone with get access on…CVE-2023-40029Container, Kubernetes & orchestration9.9CritClearML web server: XSSCVE-2024-24594AI/ML frameworks & serving9.9CritZabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCVE-2024-42327Control plane, storage & DevOps9.9CritGrafana: SQL Expressions passes user input to duckdb unsanitizedCVE-2024-9264Control plane, storage & DevOps9.9CritRed Hat OpenShift AI (notebook plane): A low-privileged data-scientist account can escalate to full cluster compromiseCVE-2025-10725AI/ML frameworks & serving9.9CritRedis: "RediShell" - authenticated user crafts a Lua script to trigger a use-after-freeCVE-2025-49844Control plane, storage & DevOps9.9CritBentoML (file upload): SSRF in the file-upload pathCVE-2025-54381AI/ML frameworks & serving9.9CritKubeVirt: Improper symlink validation in virt-handler lets a user with edit rights in one namespace escape to the hostCVE-2026-7374Container, Kubernetes & orchestration9.8CritHPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoS on the…CVE-2016-4375Firmware, BMC & network fabric9.8CritHPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CVE-2017-8979Firmware, BMC & network fabric9.8CritDell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCVE-2018-1207Firmware, BMC & network fabric9.8CritHelm: Improper certificate validation allows unauthorized clients to connect to TillerCVE-2019-1010275Container, Kubernetes & orchestration9.8CritDocker / moby: Code injection into `docker cp` via nsswitch loading a library from the container chrootCVE-2019-14271Container, Kubernetes & orchestration9.8CritHelm: Malicious chart includes sensitive host content such as /etc/passwd, or triggers DoS, when loaded as a…CVE-2019-18658Container, Kubernetes & orchestration9.8CritEnvoy: HTTP/2 request writes to the heap outside request buffers when the upstream is HTTP/1CVE-2019-18801Container, Kubernetes & orchestration9.8CritEnvoy: Header whitespace handling enables request smuggling and authorization bypassCVE-2019-18802Container, Kubernetes & orchestration9.8CritFirecracker: vsock buffer overflow producing potentially exploitable crashesCVE-2019-18960Container, Kubernetes & orchestration9.8CritDell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCVE-2019-3705Firmware, BMC & network fabric9.8CritDell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706Firmware, BMC & network fabric9.8CritDell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707Firmware, BMC & network fabric9.8CritASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU** — host-to-BMC boundary…CVE-2019-6260Firmware, BMC & network fabricPantsdown9.8Critscikit-learn / joblib: `joblib.load()` executes commands from an untrusted file via `__reduce__`CVE-2020-13092AI/ML frameworks & serving9.8CritSlurm: RPC buffer overflow in the PMIx MPI pluginCVE-2020-27745Container, Kubernetes & orchestration9.8CritVMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992Kernel, userspace & hypervisorKnown exploited9.8CritDell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCVE-2020-5344Firmware, BMC & network fabric