Graalvm

Vendor:

First CVE: Jul 23, 2019 · Active for 7 years

188
Total CVEs
More Total CVEs than 99% of tracked products
23.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Graalvm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 2019
7 years ago
Most Recent CVE
Apr 21, 2026
95 days ago

CVE Severity & Scoring

Graalvm188 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local16 (8.5%)
Network172 (91.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low100 (53.2%)
High88 (46.8%)
Unknown0 (0.0%)
User Interaction
None158 (84.0%)
Unknown0 (0.0%)
Required30 (16.0%)
Privileges Required
Low13 (6.9%)
High1 (0.5%)
None174 (92.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (188 CVEs).

188 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that t
Sep 21, 20238.882YESNO
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated b
Jul 19, 20227.570NONO
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
Nov 17, 20209.870NONO
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This
Mar 3, 20217.567NONO
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF
Aug 13, 20197.566NONO
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea
Aug 13, 20197.565NONO
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the
Aug 13, 20197.565NONO
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
Feb 7, 20209.863NONO
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms
Mar 25, 20215.957NONO
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 b
Nov 19, 20207.554NONO

Exploit Exposure

Signals from CVEs in this product scope (188 CVEs).

CISA KEV
1 CVE
0.5% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (188 CVEs).

Media Mentions

Signals from CVEs in this product scope (188 CVEs).

Top CNAs Publishing CVEs For Graalvm

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
22.3.486.00.8%00
22.3.273.81.0%00
22.3.175.41.3%00
22.3.044.51.4%00
22.2.085.01.7%00
22.1.056.320.4%00
22.0.114.80.9%00
22.0.0.295.810.2%00
21.3.9123.83.2%10
21.3.8115.20.7%00
21.3.673.81.0%00
21.3.575.41.3%00
21.3.444.51.4%00
21.3.385.01.7%00
21.3.256.320.4%00
21.3.1785.10.3%00
21.3.1646.50.4%00
21.3.1535.70.5%00
21.3.1457.10.6%00
21.3.1326.50.7%00