Bottom line: I just don't want to have to worry about this shit, so try to avoid Javascript like the plague.
[1] - https://news.ycombinator.com/item?id=13831906
[2] - https://news.ycombinator.com/item?id=13649178
2 - this is a hardware vulnerability that you could take advantage of in multiple languages.
3 - this is a Tor + windows exploit that just happens to use JS.
4 - this is a Firefox vulnerability, not a JS vulnerability
There is nothing inherently wrong with JS from a security perspective and in many ways it is a much more secure system than most, since it is constantly exposed to the internet.
But like any large ecosystem with multiple implementations and lots of inexperienced devs, there will be vulnerabilities out there.
I do respect your decision to turn of JS, but I don't agree that JS is somehow special in how insecure it is. You should also avoid running any apps written in any language at all with that logic. I'd posit that JavaScript apps are more secure than c++ apps, since the runtime itself is hardened.
2 - See 1 above.
3 - See 1 above.
4 - It's a vulnerability in a part of Firefox that's written in Javascript.
"I don't agree that JS is somehow special in how insecure it is"
I never claimed that JS was any more insecure than any other language (though fans of "safe" languages and ones whose programs and compilers can be proven correct might in fact make that argument).
Javascript has the special distinction of being the only programming language in the web browser (if you exclude HTML). If it wasn't, then the argument of whether JS was or was more insecure than the other language(s) in the web browser would relevant. But that's not the case.
"I'd posit that JavaScript apps are more secure than c++ apps"
Completely irrelevant since I don't have the choice to run C++ in my web browser.