Node.Js
Vendor:
First CVE: Jul 31, 2013 · Active for 12 years
210
Total CVEs
More Total CVEs than 99% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Node.Js over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
Jun 26, 2026
28 days ago
CVE Severity & Scoring
Node.Js210 CVEs
31%
55%
9%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (10.5%)
Network183 (87.1%)
Unknown5 (2.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low163 (77.6%)
High42 (20.0%)
Unknown5 (2.4%)
User Interaction
None182 (86.7%)
Unknown5 (2.4%)
Required23 (11.0%)
Privileges Required
Low26 (12.4%)
High3 (1.4%)
None176 (83.8%)
Unknown5 (2.4%)
Top CVEs
Signals from CVEs in this product scope (210 CVEs).
210 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2016-2107MEDIUM The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta | May 5, 2016 | 5.9 | 79 | NO | YES |
CVE-2016-2183HIGH The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak | Sep 1, 2016 | 7.5 | 77 | NO | NO |
CVE-2022-3786HIGH A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification | Nov 1, 2022 | 7.5 | 76 | NO | NO |
CVE-2022-3602HIGH A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification | Nov 1, 2022 | 7.5 | 75 | NO | NO |
CVE-2024-27983HIGH An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave so | Apr 9, 2024 | 8.2 | 74 | NO | NO |
CVE-2022-32214MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Sm | Jul 14, 2022 | 6.5 | 67 | NO | NO |
CVE-2021-22883HIGH Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This | Mar 3, 2021 | 7.5 | 67 | NO | NO |
CVE-2019-9515HIGH Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF | Aug 13, 2019 | 7.5 | 66 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (210 CVEs).
CISA KEV
1 CVE
0.5% of CVEs· 96th percentile
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
2 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.4% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (210 CVEs).
Media Mentions
Signals from CVEs in this product scope (210 CVEs).
Top CNAs Publishing CVEs For Node.Js
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.7.0 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.6.0 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.5.0 | 2 | 7.5 | 31.3% | 0 | 1 |
| 8.4.0 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.3.0 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.2.1 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.2.0 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.1.4 | 1 | 7.5 | 8.2% | 0 | 0 |
| 8.1.3 | 2 | 7.5 | 6.9% | 0 | 0 |
| 8.1.2 | 2 | 7.5 | 6.9% | 0 | 0 |
| 8.1.1 | 2 | 7.5 | 6.9% | 0 | 0 |
| 8.1.0 | 2 | 7.5 | 6.9% | 0 | 0 |
| 8.0.0 | 2 | 7.5 | 6.9% | 0 | 0 |
| 7.9.0 | 1 | 7.5 | 5.5% | 0 | 0 |
| 7.8.0 | 1 | 7.5 | 5.5% | 0 | 0 |
| 7.7.4 | 1 | 7.5 | 5.5% | 0 | 0 |
| 7.7.3 | 1 | 7.5 | 5.5% | 0 | 0 |
| 7.7.2 | 1 | 7.5 | 5.5% | 0 | 0 |
| 7.7.1 | 1 | 7.5 | 5.5% | 0 | 0 |
| 7.7.0 | 1 | 7.5 | 5.5% | 0 | 0 |