Node.Js

Vendor:

First CVE: Jul 31, 2013 · Active for 12 years

210
Total CVEs
More Total CVEs than 99% of tracked products
15.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Node.Js over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

CVE Severity & Scoring

Node.Js210 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local22 (10.5%)
Network183 (87.1%)
Unknown5 (2.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low163 (77.6%)
High42 (20.0%)
Unknown5 (2.4%)
User Interaction
None182 (86.7%)
Unknown5 (2.4%)
Required23 (11.0%)
Privileges Required
Low26 (12.4%)
High3 (1.4%)
None176 (83.8%)
Unknown5 (2.4%)

Top CVEs

Signals from CVEs in this product scope (210 CVEs).

210 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta
May 5, 20165.979NOYES
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak
Sep 1, 20167.577NONO
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification
Nov 1, 20227.576NONO
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification
Nov 1, 20227.575NONO
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave so
Apr 9, 20248.274NONO
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Sm
Jul 14, 20226.567NONO
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This
Mar 3, 20217.567NONO
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF
Aug 13, 20197.566NONO

Exploit Exposure

Signals from CVEs in this product scope (210 CVEs).

CISA KEV
1 CVE
0.5% of CVEs· 96th percentile
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
2 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (210 CVEs).

Media Mentions

Signals from CVEs in this product scope (210 CVEs).

Top CNAs Publishing CVEs For Node.Js

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.7.017.58.2%00
8.6.017.58.2%00
8.5.027.531.3%01
8.4.017.58.2%00
8.3.017.58.2%00
8.2.117.58.2%00
8.2.017.58.2%00
8.1.417.58.2%00
8.1.327.56.9%00
8.1.227.56.9%00
8.1.127.56.9%00
8.1.027.56.9%00
8.0.027.56.9%00
7.9.017.55.5%00
7.8.017.55.5%00
7.7.417.55.5%00
7.7.317.55.5%00
7.7.217.55.5%00
7.7.117.55.5%00
7.7.017.55.5%00