GNU Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for GNU products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

4

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

GNU KEVs Added by Year

Loading...

5 GNU KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-30258

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated...

High Not in CISA 29 Jul 2025
CVE-2026-24061

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Confirmed In CISA 01 Jun 2026
CVE-2014-6278

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers...

Confirmed In CISA 01 Jun 2026
CVE-2014-7169

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,...

Confirmed In CISA 28 Jan 2022
CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to...

Confirmed In CISA 28 Jan 2022

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
  • CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology