GNU Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for GNU products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
4
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
GNU KEVs Added by Year
5 GNU KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-30258
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated... |
magnusbilling | High | Not in CISA | 29 Jul 2025 |
|
CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. |
Inetutils | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2014-6278
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers... |
Bash | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,... |
Bash | Confirmed | In CISA | 28 Jan 2022 |
|
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to... |
Bash | Confirmed | In CISA | 28 Jan 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology