Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Locutus CRITICAL 9.8
CVE-2026-33993

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function i…

Fix: 3.0.25+
Fix from $2,300 2026-03-27
Locutus CRITICAL 9.8
CVE-2026-33994

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25,…

Fix: 3.0.25+
Fix from $2,300 2026-03-27
Locutus CRITICAL 9.8
CVE-2026-32304

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi…

Fix: 3.0.14+
Fix from $2,300 2026-03-13
Locutus HIGH 8.1
CVE-2026-29091

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) f…

Fix: 3.0.0+
Fix from $1,950 2026-03-06
Locutus HIGH 8.8
CVE-2026-25521

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype p…

Fix: 2.0.39+
Fix from $1,950 2026-02-04
Locutus HIGH 7.5
CVE-2021-23392

The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.

Fix: 2.0.15+
Fix from $1,950 2021-06-08
Locutus CRITICAL 9.8
CVE-2020-7719

Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

Fix: 2.0.12+
Fix from $2,300 2020-09-01
Locutus Php CRITICAL 9.8
CVE-2020-13619

php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.

Fix: after 2.0.11
Fix from $2,300 2020-07-01