Graalvm
Vendor:
First CVE: Jul 23, 2019 · Active for 7 years
188
Total CVEs
More Total CVEs than 99% of tracked products
23.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Graalvm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 2019
7 years ago
Most Recent CVE
Apr 21, 2026
95 days ago
CVE Severity & Scoring
Graalvm188 CVEs
24%
44%
29%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (8.5%)
Network172 (91.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low100 (53.2%)
High88 (46.8%)
Unknown0 (0.0%)
User Interaction
None158 (84.0%)
Unknown0 (0.0%)
Required30 (16.0%)
Privileges Required
Low13 (6.9%)
High1 (0.5%)
None174 (92.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (188 CVEs).
188 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41993HIGH The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that t | Sep 21, 2023 | 8.8 | 82 | YES | NO |
CVE-2022-34169HIGH The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated b | Jul 19, 2022 | 7.5 | 70 | NO | NO |
CVE-2020-7774CRITICAL The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. | Nov 17, 2020 | 9.8 | 70 | NO | NO |
CVE-2021-22883HIGH Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This | Mar 3, 2021 | 7.5 | 67 | NO | NO |
CVE-2019-9515HIGH Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF | Aug 13, 2019 | 7.5 | 66 | NO | NO |
CVE-2019-9514HIGH Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea | Aug 13, 2019 | 7.5 | 65 | NO | NO |
CVE-2019-9513HIGH Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the | Aug 13, 2019 | 7.5 | 65 | NO | NO |
CVE-2019-15605CRITICAL HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | Feb 7, 2020 | 9.8 | 63 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2020-8277HIGH A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 b | Nov 19, 2020 | 7.5 | 54 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (188 CVEs).
CISA KEV
1 CVE
0.5% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (188 CVEs).
Media Mentions
Signals from CVEs in this product scope (188 CVEs).
Top CNAs Publishing CVEs For Graalvm
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 22.3.4 | 8 | 6.0 | 0.8% | 0 | 0 |
| 22.3.2 | 7 | 3.8 | 1.0% | 0 | 0 |
| 22.3.1 | 7 | 5.4 | 1.3% | 0 | 0 |
| 22.3.0 | 4 | 4.5 | 1.4% | 0 | 0 |
| 22.2.0 | 8 | 5.0 | 1.7% | 0 | 0 |
| 22.1.0 | 5 | 6.3 | 20.4% | 0 | 0 |
| 22.0.1 | 1 | 4.8 | 0.9% | 0 | 0 |
| 22.0.0.2 | 9 | 5.8 | 10.2% | 0 | 0 |
| 21.3.9 | 12 | 3.8 | 3.2% | 1 | 0 |
| 21.3.8 | 11 | 5.2 | 0.7% | 0 | 0 |
| 21.3.6 | 7 | 3.8 | 1.0% | 0 | 0 |
| 21.3.5 | 7 | 5.4 | 1.3% | 0 | 0 |
| 21.3.4 | 4 | 4.5 | 1.4% | 0 | 0 |
| 21.3.3 | 8 | 5.0 | 1.7% | 0 | 0 |
| 21.3.2 | 5 | 6.3 | 20.4% | 0 | 0 |
| 21.3.17 | 8 | 5.1 | 0.3% | 0 | 0 |
| 21.3.16 | 4 | 6.5 | 0.4% | 0 | 0 |
| 21.3.15 | 3 | 5.7 | 0.5% | 0 | 0 |
| 21.3.14 | 5 | 7.1 | 0.6% | 0 | 0 |
| 21.3.13 | 2 | 6.5 | 0.7% | 0 | 0 |