Known vulnerabilities in wget

Vendor: GNU
Software: wget
Software CPE: cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wget wget is affected by 12 known vulnerabilities: 7 high, 3 medium, 2 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121013 - Memory corruption
CWE-119 High
No
No
2.2.1 07.01.2026 SB2026010713
#VU121012 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-69194
CWE-22 High
No
No
2.2.1 07.01.2026 SB2026010713
SB2026031153
#VU103688 - Exposure of sensitive information to an unauthorized actor
CVE-2021-31879
CWE-200 Low
No
No
1.21.2 06.02.2025 SB2021042961
SB2025020665
SB2025020666
and 7 more
#VU100247 - Improper input validation
CVE-2024-10524
CWE-20 Medium
No
No
1.25.0 12.11.2024 SB2024111268
SB2024111269
SB2024120382
and 7 more
#VU93077 - Improper input validation
CVE-2024-38428
CWE-20 Medium
No
No
- 22.06.2024 SB2024062208
SB2024062219
SB2024062421
and 45 more
#VU18143 - Memory corruption
CVE-2019-5953
CWE-119 High
No
No
1.20.2 06.04.2019 SB2019040601
SB2019040602
SB2019040810
and 14 more
#VU16783 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20483
CWE-200 Low
No
No
1.20.1 02.01.2019 SB2018122510
SB2019011803
SB2019020808
and 9 more
#VU8960 - Heap-based Buffer Overflow
CVE-2017-13090
CWE-122 High
No
No
- 27.10.2017 SB2017102703
SB2017102707
SB2017102801
and 12 more
#VU8959 - Heap-based Buffer Overflow
CVE-2017-13089
CWE-122 High
No
No
- 26.10.2017 SB2017102703
SB2017102707
SB2017102801
and 13 more
#VU32275 - Security Features
CVE-2016-4971
CWE-254 High
Available
No
1.18 30.06.2016 SB2016063014
SB2016070507
SB2016071408
and 7 more
#VU32477 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2014-4877
CWE-22 High
Available
No
1.16 29.10.2014 SB2014102902
SB2014111202
SB2014111203
and 6 more
#VU33335 - Improper input validation
CVE-2010-2252
CWE-20 Medium
No
No
1.13 06.07.2010 SB2010070601
SB2011101703
SB2011101301