Known vulnerabilities in Emacs

Vendor: GNU
Software: Emacs
Software CPE: cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*
Total vulnerabilities: 19
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Emacs Emacs is affected by 19 known vulnerabilities: 14 high, 2 medium, 3 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU128469 - Off-by-one Error
CVE-2026-6861
CWE-193 Low
No
No
- 29.04.2026 SB2026042980
SB2026042981
SB2026042982
and 6 more
#VU109473 - Exposure of sensitive information to an unauthorized actor
CVE-2017-1000383
CWE-200 Low
No
No
- 20.05.2025 SB2017103121
SB2025052045
#VU104117 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-1244
CWE-78 High
No
No
- 21.02.2025 SB2025022110
SB2025022111
SB2025022112
and 31 more
#VU101890 - Exposed Dangerous Method or Function
CVE-2024-53920
CWE-749 High
No
No
30.0.93 20.12.2024 SB2024122058
SB2024122059
SB20250226597
and 21 more
#VU93118 - Use of Potentially Dangerous Function
CVE-2024-39331
CWE-676 High
No
No
29.4 24.06.2024 SB2024062429
SB2024062430
SB2024062431
and 46 more
#VU87809 - Insufficient Verification of Data Authenticity
CVE-2024-30204
CWE-345 High
No
No
29.3 26.03.2024 SB2024032628
SB2024032629
SB2024032630
and 12 more
#VU87808 - Insufficient Verification of Data Authenticity
CVE-2024-30203
CWE-345 High
No
No
29.3 26.03.2024 SB2024032628
SB2024032629
SB2024032630
and 30 more
#VU87807 - Use of Potentially Dangerous Function
CVE-2024-30202
CWE-676 High
No
No
29.3 26.03.2024 SB2024032628
SB2024032629
SB2024032630
and 6 more
#VU87804 - Insufficient Verification of Data Authenticity
CVE-2024-30205
CWE-345 High
No
No
29.3 26.03.2024 SB2024032628
SB2024032629
SB2024032630
and 32 more
#VU74003 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-27985
CWE-78 High
No
No
- 24.03.2023 SB2023032405
SB2023082320
SB20240806359
and 1 more
#VU74002 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-27986
CWE-94 High
No
No
- 24.03.2023 SB2023032405
SB2023082320
SB20240806359
#VU72575 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48339
CWE-78 High
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 50 more
#VU72574 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48338
CWE-78 Low
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 14 more
#VU72573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48337
CWE-78 High
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 42 more
#VU69808 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-45939
CWE-78 High
No
No
- 01.12.2022 SB2022120142
SB2022120148
SB2022120149
and 23 more
#VU33781 - Improper input validation
CVE-2017-14482
CWE-20 High
No
No
25.3 14.09.2017 SB2017091422
SB2017092131
SB2017092015
and 9 more
#VU8419 - Improper input validation
CWE-20 High
No
No
- 13.09.2017 SB2017091310
#VU38418 - Exposure of sensitive information to an unauthorized actor
CVE-2014-9483
CWE-200 Medium
No
No
- 28.08.2017 SB2017082816
#VU33935 - Improper input validation
CVE-2012-3479
CWE-20 Medium
No
No
23.3 25.08.2012 SB2012082501
SB2012100133
SB2012081617