Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Luajit

First CVE: Nov 29, 2019Active for: 7 yearsTotal CVEs: 6

Luajit is a lightweight, high-performance just-in-time compiler for Lua that is embedded across a wide range of applications, game engines, and systems software despite its narrow product footprint, making its vulnerability profile consequential out of proportion to its volume. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including out-of-bounds reads, type confusion, NULL-pointer dereferences, and stack-based buffer overflows, reflecting the low-level code-generation and runtime demands of a JIT compiler. Defenders should inventory upstream products that bundle this library and treat Luajit updates as supply-chain dependencies; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Luajit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2019
6 years ago
Most Recent CVE
Jul 7, 2025
382 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-25176CRITICAL
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
Jul 7, 20259.828NONO
CVE-2020-15890HIGH
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
Jul 21, 20207.527NONO
CVE-2019-19391CRITICAL
In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, becau
Nov 29, 20199.126NONO
CVE-2024-25178CRITICAL
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
Jul 7, 20259.124NONO
CVE-2020-24372HIGH
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
Aug 17, 20207.523NONO
CVE-2024-25177HIGH
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
Jul 7, 20257.520NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Luajit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Luajit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Luajit's Products

View all 1 CNAs →

Top CWEs