Wpe Webkit
Vendor:
First CVE: Jun 19, 2018 · Active for 8 years
24
Total CVEs
More Total CVEs than 95% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
25.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Wpe Webkit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2018
8 years ago
Most Recent CVE
Sep 15, 2025
312 days ago
CVE Severity & Scoring
Wpe Webkit24 CVEs
38%
42%
21%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (12.5%)
Network21 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (37.5%)
Unknown0 (0.0%)
Required15 (62.5%)
Privileges Required
Low2 (8.3%)
High0 (0.0%)
None22 (91.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2294HIGH Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jul 28, 2022 | 8.8 | 91 | YES | NO |
CVE-2025-31277HIGH The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Proc | Jul 30, 2025 | 8.8 | 76 | YES | NO |
CVE-2025-6558HIGH Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted | Jul 15, 2025 | 8.8 | 73 | YES | NO |
CVE-2022-32893HIGH An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing mali | Aug 24, 2022 | 8.8 | 71 | YES | NO |
CVE-2021-30952HIGH An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Process | Aug 24, 2021 | 7.8 | 70 | YES | NO |
CVE-2019-8720HIGH A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addre | Mar 6, 2023 | 8.8 | 65 | YES | NO |
CVE-2018-12293HIGH The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE Web | Jun 19, 2018 | 8.8 | 41 | NO | YES |
CVE-2025-43343CRITICAL The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciou | Sep 15, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-43342CRITICAL A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watc | Sep 15, 2025 | 9.8 | 31 | NO | NO |
CVE-2020-10018CRITICAL WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary c | Mar 2, 2020 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
6 CVEs
25.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Wpe Webkit
Top CWEs
Versions
No cataloged versions.