Rvc Project maintains a retrieval-based voice-conversion webUI application, a specialized audio-processing tool that operates in a niche but architecturally prominent segment of machine-learning and speech-synthesis deployments. The vendor's vulnerability disclosures reflect the scope of a focused, open-source project rather than a broad portfolio; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rvc Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-43847CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable | May 5, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-43852CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variabl | May 5, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-43843CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 a | May 5, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-43851CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variabl | May 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-43850CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable ta | May 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-43849CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b va | May 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-43848CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable | May 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-43846CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable | May 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-43845CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes us | May 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-43844CRITICAL Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among | May 5, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rvc Project.
Media articles that mention a CVE ID that affects a product developed by Rvc Project — matched by CVE ID, not by vendor name.