Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quickjs HIGH 7.5
CVE-2025-69654

A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` …

Fix: 2025-12-11+
Fix from $1,950 2026-03-06
Quickjs MEDIUM 6.5
CVE-2025-69653

A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb…

Fix: 2025-12-11+
Fix from $1,600 2026-03-06
Quickjs HIGH 8.8
CVE-2025-62495

An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode b…

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Quickjs HIGH 8.8
CVE-2025-62496

A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string w…

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Quickjs HIGH 8.8
CVE-2025-62490

In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a …

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Quickjs HIGH 8.8
CVE-2025-62491

A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promis…

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Quickjs HIGH 8.8
CVE-2025-62494

A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if …

Fix: 2025-09-13+
Fix from $1,950 2025-10-16
Quickjs MEDIUM 6.5
CVE-2025-62492

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexO…

Fix: 2025-09-13+
Fix from $1,600 2025-10-16
Quickjs MEDIUM 6.5
CVE-2025-62493

A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required …

Fix: 2025-09-13+
Fix from $1,600 2025-10-16
Quickjs HIGH 7.5
CVE-2023-48183

QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

Fix: 2023-12-09+
Fix from $1,950 2024-04-23
Quickjs HIGH 7.5
CVE-2023-31922

QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.

No fix yet
Fix from $1,950 2023-05-12
Quickjs HIGH 7.5
CVE-2020-22876

Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 r…

Fix: 2020-07-05+
Fix from $1,950 2021-07-13