Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lua

First CVE: Sep 4, 2014Active for: 12 yearsTotal CVEs: 17
49.9
VTI Score
TOP TARGET

Lua is a lightweight, widely embedded scripting language used across a broad ecosystem of applications, game engines, and systems software, making its interpreter a deceptively high-impact component despite the narrow product scope. Vulnerabilities in the Lua interpreter skew toward serious outcomes and tend to acquire public exploit code; they recur through memory-safety weakness classes including out-of-bounds reads and writes, use-after-free conditions, type confusion, and improper buffer-boundary enforcement that reflect the interpreter's C implementation and tight integration with host systems. Defenders should track Lua interpreter updates closely wherever the runtime is embedded, as a single flaw can affect numerous downstream products; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lua over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2014
11 years ago
Most Recent CVE
Apr 10, 2023
1,201 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-6706HIGH
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which
Jan 23, 20197.544NOYES
CVE-2022-33099HIGH
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
Jul 1, 20227.527NONO
CVE-2021-45985HIGH
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
Apr 10, 20237.525NONO
CVE-2020-24342HIGH
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
Aug 13, 20207.825NONO
CVE-2021-32918HIGH
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running unde
May 13, 20217.524NONO
CVE-2020-15889CRITICAL
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.
Jul 21, 20209.824NONO
CVE-2020-15888HIGH
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
Jul 21, 20208.824NONO
CVE-2014-5461MEDIUM
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of
Sep 4, 20145.024NONO
CVE-2022-28805CRITICAL
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a sy
Apr 8, 20229.123NONO
CVE-2020-24369HIGH
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
Aug 17, 20207.523NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
47%
41%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (29.4%)
Network11 (64.7%)
Unknown1 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High1 (5.9%)
Unknown1 (5.9%)
User Interaction
None12 (70.6%)
Unknown1 (5.9%)
Required4 (23.5%)
Privileges Required
Low2 (11.8%)
High0 (0.0%)
None14 (82.4%)
Unknown1 (5.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lua.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lua — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lua's Products

View all 2 CNAs →

Top CWEs