Emacs
Vendor:
First CVE: Apr 18, 2000 · Active for 26 years
36
Total CVEs
More Total CVEs than 97% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Emacs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2000
26 years ago
Most Recent CVE
Apr 22, 2026
94 days ago
CVE Severity & Scoring
Emacs36 CVEs
22%
28%
44%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (36.1%)
Network4 (11.1%)
Unknown19 (52.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (47.2%)
High0 (0.0%)
Unknown19 (52.8%)
User Interaction
None6 (16.7%)
Unknown19 (52.8%)
Required11 (30.6%)
Privileges Required
Low5 (13.9%)
High0 (0.0%)
None12 (33.3%)
Unknown19 (52.8%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48337CRITICAL GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function i | Feb 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-14482HIGH GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies | Sep 14, 2017 | 8.8 | 29 | NO | NO |
CVE-2012-0035HIGH Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expr | Jan 19, 2012 | 9.3 | 29 | NO | NO |
CVE-2003-1232MEDIUM Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary co | Dec 31, 2003 | 5.1 | 29 | NO | YES |
CVE-2024-39331CRITICAL In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org | Jun 23, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-27986HIGH emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in | Mar 9, 2023 | 7.8 | 25 | NO | NO |
CVE-2023-27985HIGH emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop | Mar 9, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-48339HIGH An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir | Feb 20, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-45939HIGH GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function i | Nov 28, 2022 | 7.8 | 25 | NO | NO |
CVE-2012-3479MEDIUM lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows | Aug 25, 2012 | 6.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Emacs
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 27.2-8.el9 | 1 | 7.8 | 0.5% | 0 | 0 |
| 26.1-9.el8 | 1 | 7.8 | 0.5% | 0 | 0 |
| 24.4 | 1 | 7.5 | 2.9% | 0 | 0 |
| 24.2 | 4 | 3.3 | 0.3% | 0 | 0 |
| 24.1 | 5 | 4.0 | 1.0% | 0 | 0 |
| 23.4 | 6 | 4.9 | 1.3% | 0 | 0 |
| 23.3 | 5 | 4.0 | 1.0% | 0 | 0 |
| 23.2 | 6 | 4.9 | 1.3% | 0 | 0 |
| 23.1 | 6 | 4.5 | 0.7% | 0 | 0 |
| 22.3 | 6 | 4.5 | 0.7% | 0 | 0 |
| 22.2 | 6 | 4.5 | 0.7% | 0 | 0 |
| 22.1 | 6 | 4.5 | 0.7% | 0 | 0 |
| 21.4 | 6 | 4.5 | 0.8% | 0 | 0 |
| 21.3.1 | 6 | 4.9 | 1.3% | 0 | 0 |
| 21.3 | 7 | 4.9 | 1.3% | 0 | 0 |
| 21.2.1 | 6 | 4.6 | 1.2% | 0 | 1 |
| 21.2 | 6 | 4.5 | 0.8% | 0 | 0 |
| 21.1 | 6 | 4.5 | 0.8% | 0 | 0 |
| 21 | 6 | 5.0 | 1.0% | 0 | 0 |
| 20.7 | 6 | 4.5 | 0.8% | 0 | 0 |