Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wondershare

First CVE: Nov 2, 2020Active for: 6 yearsTotal CVEs: 30
60.1
VTI Score
TOP TARGET

Wondershare's vulnerability footprint concentrates across a modestly sized portfolio of consumer-facing productivity and media software—including tools such as Dr.Fone, Filmora, MobileTransfers, RepairIt, and Edraw—that target end-users performing device recovery, video editing, and data management tasks. The vendor's disclosures cluster durably around path-traversal and privilege-escalation weaknesses, with recurring patterns of untrusted search paths, unquoted search-path elements, and incorrect permission assignment on critical resources that reflect the local-execution context and elevated-privilege operations these utilities demand. A meaningful share of the vendor's vulnerabilities frequently acquire public exploit code, reflecting their appeal to straightforward local-privilege and elevation scenarios on Windows systems. Defenders should treat updates for these tools as routine maintenance priorities, particularly in environments where users retain administrative or system-level access; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wondershare over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2020
5 years ago
Most Recent CVE
Feb 12, 2026
162 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44596CRITICAL
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "Inst
Apr 29, 20229.857NOYES
CVE-2021-44595HIGH
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and exec
Apr 29, 20228.853NOYES
CVE-2023-31748HIGH
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.
May 24, 20237.836NOYES
CVE-2023-31747HIGH
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the component NativePushService. This vulnerability allows attackers
May 23, 20237.836NOYES
CVE-2025-10644CRITICAL
Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondersha
Sep 17, 20259.434NONO
CVE-2023-27010HIGH
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escalate privileges via modifying or overwr
Mar 13, 20237.834NOYES
CVE-2025-10643CRITICAL
Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installati
Sep 17, 20259.133NONO
CVE-2022-50901HIGH
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit
Jan 13, 20267.828NONO
CVE-2022-50900HIGH
Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit
Jan 13, 20267.828NONO
CVE-2023-27762HIGH
An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.
Apr 4, 20237.825NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
87%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowHighCritical
Attack Vector
Local26 (86.7%)
Network4 (13.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (53.3%)
Unknown0 (0.0%)
Required14 (46.7%)
Privileges Required
Low14 (46.7%)
High0 (0.0%)
None16 (53.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wondershare.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wondershare — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wondershare's Products

View all 4 CNAs →

Top CWEs