Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Facebook

First CVE: Feb 8, 2008Active for: 18 yearsTotal CVEs: 135
77.4
VTI Score
TOP TARGET

Facebook's vulnerability footprint concentrates in a focused set of infrastructure and runtime products—most notably the HHVM virtual machine, Hermes JavaScript engine, Thrift middleware, and Proxygen HTTP library—that power internal and external service delivery at scale. Though the product portfolio remains relatively narrow, these components sit deep in production stacks and reach significant prominence in the vulnerability landscape, and vulnerabilities affecting them skew strongly toward critical-severity outcomes. The exposure recurs persistently through memory-safety and deserialization weakness classes: out-of-bounds reads and writes, use-after-free conditions, buffer-boundary violations, and untrusted deserialization, reflecting the low-level performance and parsing demands of runtime systems and middleware. Defenders tracking these products should prioritize patching for the severity risk they carry; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
135
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
1.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Facebook over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2008
18 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(33 total)

Top CVEs

Signals from CVEs in this vendor scope (135 CVEs).

135 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-55182CRITICAL
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve
Dec 3, 202510.099YESYES
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2025-55184HIGH
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following pa
Dec 11, 20257.583NOYES
CVE-2025-55183MEDIUM
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the foll
Dec 11, 20255.368NONO
CVE-2008-5711HIGH
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value.
Dec 24, 20089.359NOYES
CVE-2008-0660HIGH
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Face
Feb 8, 20089.358NOYES
CVE-2021-24040CRITICAL
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execu
Sep 10, 20219.852NOYES
CVE-2025-67779HIGH
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Compo
Dec 12, 20257.550NONO
CVE-2026-23864HIGH
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom
Jan 26, 20267.534NONO
CVE-2026-44909HIGH
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETT
Jul 23, 20267.533NONO
View all 135 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products135 CVEs
16%
44%
41%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (4.4%)
Network120 (88.9%)
Unknown9 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low116 (85.9%)
High10 (7.4%)
Unknown9 (6.7%)
User Interaction
None113 (83.7%)
Unknown9 (6.7%)
Required13 (9.6%)
Privileges Required
Low4 (3.0%)
High0 (0.0%)
None122 (90.4%)
Unknown9 (6.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (135 CVEs).

CISA KEV
2 CVEs
1.5% of CVEs· 99th percentile
Metasploit
2 CVEs
1.5% of CVEs· 97th percentile
Nuclei
2 CVEs
1.5% of CVEs· 95th percentile
ExploitDB
5 CVEs
3.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Facebook.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Facebook — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Facebook's Products

View all 7 CNAs →

Top CWEs