Grub 2
Vendor:
First CVE: Dec 1, 2009 · Active for 16 years
49
Total CVEs
Bottom 1%
5.4
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Grub 2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2009
16 years ago
Most Recent CVE
Nov 18, 2025
248 days ago
CVE Severity & Scoring
Grub 249 CVEs
51%
45%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local41 (83.7%)
Network4 (8.2%)
Unknown1 (2.0%)
Physical3 (6.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (65.3%)
High16 (32.7%)
Unknown1 (2.0%)
User Interaction
None43 (87.8%)
Unknown1 (2.0%)
Required5 (10.2%)
Privileges Required
Low15 (30.6%)
High22 (44.9%)
None11 (22.4%)
Unknown1 (2.0%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-61662HIGH A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after i | Nov 18, 2025 | 7.8 | 29 | NO | NO |
CVE-2025-0678HIGH A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the inter | Mar 3, 2025 | 7.8 | 27 | NO | NO |
CVE-2020-25632HIGH A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module i | Mar 3, 2021 | 8.2 | 27 | NO | NO |
CVE-2020-10713HIGH A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure | Jul 30, 2020 | 8.2 | 27 | NO | NO |
CVE-2025-1125HIGH When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however i | Mar 3, 2025 | 7.8 | 26 | NO | NO |
CVE-2024-56737HIGH GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem. | Dec 29, 2024 | 8.8 | 26 | NO | NO |
CVE-2021-20233HIGH A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single qu | Mar 3, 2021 | 8.2 | 26 | NO | NO |
CVE-2024-45782HIGH A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver performs a strcpy() using the user-provided volume name as i | Mar 3, 2025 | 7.8 | 25 | NO | NO |
CVE-2022-28733HIGH Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Unde | Jul 20, 2023 | 8.1 | 25 | NO | NO |
CVE-2020-27779HIGH A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory crea | Mar 3, 2021 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Grub 2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.02 | 1 | 7.4 | 1.1% | 0 | 0 |
| 2.01 | 1 | 7.4 | 1.1% | 0 | 0 |
| 2.00 | 1 | 7.4 | 1.1% | 0 | 0 |
| 1.99 | 1 | 7.4 | 1.1% | 0 | 0 |
| 1.98 | 1 | 7.4 | 1.1% | 0 | 0 |
| 1.97 | 1 | 7.2 | 0.6% | 0 | 0 |