Meta Platforms, Inc.
First CVE: Dec 3, 2018Active for: 8 years
184
CVEs Published
More CVEs Published than 78% of tracked CNAs
20.4
Avg CVEs / Year
More Avg CVEs / Year than 68% of tracked CNAs
8.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked CNAs
2.7%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Meta Platforms, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 2018
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Meta Platforms, Inc. as a CNA, regardless of affected vendor or product.
184 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55182CRITICAL A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve | Dec 3, 2025 | 10.0 | 99 | YES | YES |
CVE-2019-18426HIGH A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Ex | Jan 21, 2020 | 8.2 | 94 | YES | YES |
CVE-2019-3568CRITICAL A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects W | May 14, 2019 | 9.8 | 86 | YES | NO |
CVE-2025-55184HIGH A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following pa | Dec 11, 2025 | 7.5 | 83 | NO | YES |
CVE-2025-27363HIGH An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to Tru | Mar 11, 2025 | 8.1 | 79 | YES | NO |
CVE-2025-55183MEDIUM An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the foll | Dec 11, 2025 | 5.3 | 68 | NO | NO |
CVE-2025-55177MEDIUM Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 | Aug 29, 2025 | 5.4 | 66 | YES | NO |
CVE-2019-11932HIGH A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19. | Oct 3, 2019 | 8.8 | 64 | NO | YES |
CVE-2021-24040CRITICAL Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execu | Sep 10, 2021 | 9.8 | 52 | NO | YES |
CVE-2025-67779HIGH It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Compo | Dec 12, 2025 | 7.5 | 50 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA184 CVEs
18%
42%
39%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (10.3%)
Network163 (88.6%)
Unknown0 (0.0%)
Physical2 (1.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low164 (89.1%)
High20 (10.9%)
Unknown0 (0.0%)
User Interaction
None155 (84.2%)
Unknown0 (0.0%)
Required29 (15.8%)
Privileges Required
Low20 (10.9%)
High0 (0.0%)
None164 (89.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (184 CVEs).
CISA KEV
5 CVEs
2.7% of CVEs· 93rd percentile
Metasploit
1 CVE
0.5% of CVEs· 83rd percentile
Nuclei
2 CVEs
1.1% of CVEs· 80th percentile
ExploitDB
4 CVEs
2.2% of CVEs· 89th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Meta Platforms, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Meta Platforms, Inc. as a CNA — matched by CVE ID, not by organization name.