Webassembly Micro Runtime
Vendor:
First CVE: Nov 22, 2023 · Active for 2 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webassembly Micro Runtime over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2023
2 years ago
Most Recent CVE
Nov 25, 2025
241 days ago
CVE Severity & Scoring
Webassembly Micro Runtime11 CVEs
55%
45%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (54.5%)
Network5 (45.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None10 (90.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27532HIGH wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types. | Nov 8, 2024 | 7.5 | 25 | NO | NO |
CVE-2025-64713HIGH WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpret | Nov 25, 2025 | 7.4 | 24 | NO | NO |
CVE-2023-48105HIGH An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_byte | Nov 22, 2023 | 7.5 | 23 | NO | NO |
CVE-2024-25431HIGH An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi | Nov 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2025-64704MEDIUM WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instructi | Nov 25, 2025 | 5.5 | 20 | NO | NO |
CVE-2024-34251HIGH An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_t | May 6, 2024 | 7.5 | 20 | NO | NO |
CVE-2025-58749MEDIUM WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit nor | Sep 16, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-54126MEDIUM The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. | Jul 29, 2025 | 5.3 | 19 | NO | NO |
CVE-2024-34250MEDIUM A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "was | May 6, 2024 | 6.2 | 18 | NO | NO |
CVE-2025-43853MEDIUM The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. | May 15, 2025 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Webassembly Micro Runtime
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 2 | 6.8 | 0.5% | 0 | 0 |
| 1.2.3 | 1 | 7.5 | 1.0% | 0 | 0 |