Meta Platforms, Inc.

First CVE: Dec 3, 2018Active for: 8 years
184
CVEs Published
More CVEs Published than 78% of tracked CNAs
20.4
Avg CVEs / Year
More Avg CVEs / Year than 68% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked CNAs
2.7%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by Meta Platforms, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 2018
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Meta Platforms, Inc. as a CNA, regardless of affected vendor or product.

184 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve
Dec 3, 202510.099YESYES
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Ex
Jan 21, 20208.294YESYES
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects W
May 14, 20199.886YESNO
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following pa
Dec 11, 20257.583NOYES
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to Tru
Mar 11, 20258.179YESNO
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the foll
Dec 11, 20255.368NONO
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78
Aug 29, 20255.466YESNO
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.
Oct 3, 20198.864NOYES
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execu
Sep 10, 20219.852NOYES
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Compo
Dec 12, 20257.550NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA184 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local19 (10.3%)
Network163 (88.6%)
Unknown0 (0.0%)
Physical2 (1.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low164 (89.1%)
High20 (10.9%)
Unknown0 (0.0%)
User Interaction
None155 (84.2%)
Unknown0 (0.0%)
Required29 (15.8%)
Privileges Required
Low20 (10.9%)
High0 (0.0%)
None164 (89.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (184 CVEs).

CISA KEV
5 CVEs
2.7% of CVEs· 93rd percentile
Metasploit
1 CVE
0.5% of CVEs· 83rd percentile
Nuclei
2 CVEs
1.1% of CVEs· 80th percentile
ExploitDB
4 CVEs
2.2% of CVEs· 89th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Meta Platforms, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Meta Platforms, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs