Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpewebkit

First CVE: Jun 19, 2018Active for: 8 yearsTotal CVEs: 24
73.5
VTI Score
TOP TARGET

WPEWebKit is an embedded web engine optimized for low-resource environments and IoT devices, with a relatively narrow product footprint concentrated on its core WebKit implementation. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and have an elevated tendency to be confirmed as exploited in the wild and cataloged by CISA, reflecting the engine's role in rendering untrusted web content in constrained deployment scenarios. The exposure recurs through memory-safety and input-handling weakness classes including improper input validation, out-of-bounds writes, use-after-free conditions, and buffer-boundary violations—characteristic of a browser engine that must parse and execute complex, adversary-controlled content. Despite the modest product count, the vendor's prominence in embedded systems and the security-critical nature of web rendering make its advisories relevant to defenders managing IoT and edge-device inventories. Current severity, exploitation activity, and CVE counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
25.0%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpewebkit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2018
8 years ago
Most Recent CVE
Sep 15, 2025
312 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2294HIGH
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Jul 28, 20228.891YESNO
CVE-2025-31277HIGH
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Proc
Jul 30, 20258.876YESNO
CVE-2025-6558HIGH
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted
Jul 15, 20258.873YESNO
CVE-2022-32893HIGH
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing mali
Aug 24, 20228.871YESNO
CVE-2021-30952HIGH
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Process
Aug 24, 20217.870YESNO
CVE-2019-8720HIGH
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addre
Mar 6, 20238.865YESNO
CVE-2018-12293HIGH
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE Web
Jun 19, 20188.841NOYES
CVE-2025-43343CRITICAL
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciou
Sep 15, 20259.832NONO
CVE-2025-43342CRITICAL
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watc
Sep 15, 20259.831NONO
CVE-2020-10018CRITICAL
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary c
Mar 2, 20209.831NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
38%
42%
21%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (12.5%)
Network21 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (37.5%)
Unknown0 (0.0%)
Required15 (62.5%)
Privileges Required
Low2 (8.3%)
High0 (0.0%)
None22 (91.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
6 CVEs
25.0% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpewebkit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpewebkit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpewebkit's Products

View all 4 CNAs →

Top CWEs