Jxcore is a runtime environment for executing JavaScript applications, with reported vulnerabilities centered on its core product line. The durable signal focuses on certificate validation weaknesses, reflecting the security-critical nature of TLS handling in a runtime that may facilitate network communication. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jxcore over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70045HIGH An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnaut | Feb 23, 2026 | 7.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jxcore.
Media articles that mention a CVE ID that affects a product developed by Jxcore — matched by CVE ID, not by vendor name.