Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Espruino

First CVE: May 31, 2018Active for: 8 yearsTotal CVEs: 19
43.3
VTI Score
High

Espruino is a JavaScript runtime and firmware platform for resource-constrained microcontrollers and embedded systems, positioning itself as an accessible entry point for embedded development. Vulnerabilities affecting the platform skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety weakness classes including out-of-bounds writes and reads, buffer overflows, and improper bounds checking—endemic to interpreter codebases operating in memory-limited environments. Defenders deploying Espruino-based devices should monitor vendor advisories and consider memory-safety implications when integrating user-supplied code; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Espruino over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2018
8 years ago
Most Recent CVE
Feb 7, 2024
900 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-19693CRITICAL
An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint.
Apr 4, 20239.831NONO
CVE-2020-22884CRITICAL
Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code.
Jul 13, 20219.829NONO
CVE-2022-25465HIGH
Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.
Mar 5, 20227.826NONO
CVE-2022-25044HIGH
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
Mar 5, 20227.826NONO
CVE-2021-46325HIGH
Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.
Jan 20, 20227.825NONO
CVE-2021-46324HIGH
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
Jan 20, 20227.825NONO
CVE-2020-23257HIGH
Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c.
Apr 4, 20237.523NONO
CVE-2018-11595HIGH
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow
May 31, 20187.823NONO
CVE-2018-11598HIGH
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or
May 31, 20187.122NONO
CVE-2018-11593HIGH
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow dur
May 31, 20187.122NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
37%
53%
11%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local14 (73.7%)
Network5 (26.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (26.3%)
Unknown0 (0.0%)
Required14 (73.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Espruino.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Espruino — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Espruino's Products

View all 1 CNAs →

Top CWEs