CVE Tools

Smci

5 CVEs tracked since 2025. Since Nov 2025, none of them reached CISA KEV.

Smci CVEs per month

Nov 2025 to Nov 2025. Point at a month, or focus the strip and use the arrow keys.
Smci CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-1150

Products

The products that kept showing up in Smci's monthly top three, with their CVEs summed over those months.

  1. Mbd-x13sedw-f31 month
  2. Sys-111c-nr11 month
  3. X13SEDW-F11 month

Latest CVEs

The 14 most recently published vulnerabilities affecting Smci.

  1. CVE-2026-3821Supermicro SMASH service contain an Arbitrary code execution issue8.8
  2. CVE-2026-3820Supermicro BMC's SMTP service contains a command injection vulnerability7.2
  3. CVE-2025-12007Supermicro BMC firmware update validation bypass8.4
  4. CVE-2025-12006Supermicro BMC firmware update validation bypass7.2
  5. CVE-2025-8727A stack buffer overflow vulnerability exists in the Supermicro BMC Web function(SSL).7.2
  6. CVE-2025-8404Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library5.5
  7. CVE-2025-8076A stack buffer overflow vulnerability exists in the Supermicro BMC Web function7.2
  8. CVE-2025-7623Supermicro BMC SMASH services has a Stack-based buffer overflow vulnerability5.4
  9. CVE-2025-7704Supermicro BMC SMASH services has a Stack-based buffer overflow vulnerability5.4
  10. CVE-2025-7937Supermicro BMC firmware update validation bypass7.2
  11. CVE-2025-6198Supermicro BMC firmware update validation bypass7.2
  12. CVE-2024-10239fld->used_bytes without sanity check causes stack overflow7.2
  13. CVE-2024-10238fld->used_bytes without sanity check causes stack overflow7.2
  14. CVE-2024-10237SMC BMC Firmware Image Authentication Design Issue7.2

The record

Peak rank
#166 in Nov 2025
Busiest month shown
Nov 2025, 5 CVEs
Months with a KEV entry
0 since Nov 2025
Monthly snapshots
1 since 2025
Smci's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store