Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

gimp

About This Vendor

gimp is a technology vendor producing software and infrastructure products. As a software provider, gimp's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of gimp's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 64 known vulnerabilities from gimp. This includes 1 critical-severity issue and 41 high-severity issues that represent significant risk. These vulnerabilities affect 13 distinct products across gimp's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2005 through 2026, indicating decades of continuous security attention and research. Organizations deploying gimp products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2005-0654 2005-05-02 2025-04-03 - 5.0 Likely
CVE-2006-3404 2006-07-06 2025-04-03 - 5.1 Unknown
CVE-2007-2356 2007-04-30 2025-04-09 - 6.8 Likely
CVE-2007-3126 2007-06-08 2025-04-09 - 5.0 Likely
CVE-2007-2949 2007-07-04 2025-04-09 - 6.8 Likely
CVE-2006-4519 2007-07-10 2025-04-09 - 6.8 Likely
CVE-2009-0581 2009-03-23 2025-04-09 - 4.3 Likely
CVE-2009-0723 2009-03-23 2025-04-09 - 9.3 Likely
CVE-2009-0733 2009-03-23 2025-04-09 - 9.3 Likely
CVE-2009-1570 2009-11-13 2025-04-09 - 9.3 Likely
CVE-2009-3909 2009-11-19 2025-04-09 - 9.3 Likely
CVE-2010-4540 2011-01-07 2025-04-11 - 6.8 Likely
CVE-2010-4541 2011-01-07 2025-04-11 - 9.3 Likely
CVE-2010-4542 2011-01-07 2025-04-11 - 6.8 Likely
CVE-2010-4543 2011-01-07 2025-04-11 - 7.5 Likely
CVE-2011-1178 2011-06-06 2025-04-11 - 6.8 Likely
CVE-2011-1782 2011-07-27 2025-04-11 - 7.5 Likely
CVE-2011-2896 2011-08-19 2025-04-11 - 5.1 Unknown
CVE-2012-2763 2012-07-12 2025-04-11 - 7.5 Likely
CVE-2012-3236 2012-07-12 2025-04-11 - 4.3 Likely
CVE-2012-3402 2012-08-25 2025-04-11 - 6.8 Likely
CVE-2012-3403 2012-08-25 2025-04-11 - 6.8 Likely
CVE-2012-3481 2012-08-25 2025-04-11 - 6.8 Likely
CVE-2012-4245 2012-08-31 2025-04-11 - 6.8 Likely
CVE-2012-5576 2012-12-18 2025-04-11 - 7.5 Likely
CVE-2013-1913 2013-12-12 2025-04-11 - 6.8 Likely
CVE-2013-1978 2013-12-12 2025-04-11 - 6.8 Likely
CVE-2016-4994 2016-07-12 2025-04-12 7.8 6.8 Likely
CVE-2017-17784 2017-12-20 2025-04-20 7.8 6.8 Likely
CVE-2017-17785 2017-12-20 2025-04-20 7.8 6.8 Likely
CVE-2017-17786 2017-12-20 2025-04-20 7.8 6.8 Likely
CVE-2017-17787 2017-12-20 2025-04-20 7.8 6.8 Likely
CVE-2017-17788 2017-12-20 2025-04-20 5.5 4.3 Likely
CVE-2017-17789 2017-12-20 2025-04-20 7.8 6.8 Likely
CVE-2018-12713 2018-06-24 2024-11-21 9.1 6.4 Likely
CVE-2021-45463 2021-12-23 2025-11-03 7.8 6.8 Likely
CVE-2022-30067 2022-05-17 2024-11-21 5.5 4.3 Likely
CVE-2022-32990 2022-06-24 2024-11-21 5.5 4.3 Likely
CVE-2023-44441 2024-05-03 2025-11-04 7.8 - -
CVE-2023-44442 2024-05-03 2025-11-04 7.8 - -
CVE-2023-44443 2024-05-03 2025-08-14 7.8 - -
CVE-2023-44444 2024-05-03 2025-11-04 7.8 - -
CVE-2025-2760 2025-04-23 2025-11-03 7.8 - -
CVE-2025-2761 2025-04-23 2025-11-03 7.8 - -
CVE-2025-5473 2025-06-06 2025-11-03 8.8 - -
CVE-2025-6035 2025-06-13 2026-01-08 6.1 - -
CVE-2025-8672 2025-08-11 2025-09-12 7.8 - -
CVE-2025-10920 2025-10-29 2025-11-04 7.8 - -
CVE-2025-10921 2025-10-29 2025-11-04 7.8 - -
CVE-2025-10922 2025-10-29 2025-11-04 7.8 - -
CVE-2025-10923 2025-10-29 2025-11-04 7.8 - -
CVE-2025-10924 2025-10-29 2025-11-04 7.8 - -
CVE-2025-10925 2025-10-29 2025-11-04 7.8 - -
CVE-2025-10934 2025-10-29 2025-11-04 7.8 - -
CVE-2025-14422 2025-12-23 2026-01-20 7.8 - -
CVE-2025-14423 2025-12-23 2026-01-20 7.8 - -
CVE-2025-14424 2025-12-23 2026-01-20 7.8 - -
CVE-2025-14425 2025-12-23 2026-01-20 7.8 - -
CVE-2025-15059 2026-01-23 2026-02-26 7.8 - -
CVE-2026-0797 2026-02-20 2026-02-24 7.8 - -
CVE-2026-2044 2026-02-20 2026-02-24 7.8 - -
CVE-2026-2045 2026-02-20 2026-02-24 7.8 - -
CVE-2026-2047 2026-02-20 2026-02-24 7.8 - -
CVE-2026-2048 2026-02-20 2026-02-24 7.8 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for gimp by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with gimp's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.