Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webkit

First CVE: Jul 14, 2008Active for: 18 yearsTotal CVEs: 11
35.1
VTI Score
Medium

WebKit is a rendering engine embedded across browsers, email clients, and web-view components in applications on multiple platforms, giving its vulnerabilities disproportionate reach despite a narrow product portfolio. The recurring weakness classes—use-after-free conditions, type confusion, input-validation gaps, cross-site scripting, and out-of-bounds reads—reflect the parsing and memory-safety demands of a layout and JavaScript engine that processes untrusted content from the web. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webkit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2008
18 years ago
Most Recent CVE
Oct 16, 2020
2,107 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-9951HIGH
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code exec
Oct 16, 20208.828NONO
CVE-2020-9948HIGH
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execut
Oct 16, 20208.828NONO
CVE-2018-4209HIGH
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSE
Jan 11, 20198.828NONO
CVE-2018-12294HIGH
WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use after free for a WebCore::TextureMapperLaye
Jun 19, 20188.826NONO
CVE-2020-9952HIGH
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.
Oct 16, 20207.124NONO
CVE-2010-1766HIGH
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products,
Jul 22, 20107.521NONO
CVE-2016-9643HIGH
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) foll
Mar 7, 20177.520NONO
CVE-2008-1590MEDIUM
JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitra
Jul 14, 20086.819NONO
CVE-2008-6059MEDIUM
xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which al
Feb 5, 20095.017NONO
CVE-2016-9642MEDIUM
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
Feb 3, 20175.516NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
36%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (9.1%)
Network6 (54.5%)
Unknown4 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High0 (0.0%)
Unknown4 (36.4%)
User Interaction
None1 (9.1%)
Unknown4 (36.4%)
Required6 (54.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (63.6%)
Unknown4 (36.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webkit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webkit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webkit's Products

View all 2 CNAs →

Top CWEs