wpewebkit records
24 published records for vendor wpewebkit.
Researcher profile
- Entered KEV
- 6 · 25%
- Weaponized
- 6 · 25%
- Pre-auth RCE
- 5
- With a fix record
- 100%
- Median publish → KEV
- 18 days
Recurring classes
- CWE-20 Improper Input Validation4
- CWE-416 Use After Free3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound2
- CWE-290 Authentication Bypass by Spoofing1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
86Now | CVE-2022-2294Weaponized | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption viagoogle · chrome · CWE-787 | High8.8 | KEV | 70.5% | Jul 27, 2022 |
68This week | CVE-2022-32893Weaponized | An out-of-bounds write issue was addressed with improved bounds checking.apple · safari · CWE-787 | High8.8 | KEV | 9.9% | Aug 24, 2022 |
68This week | CVE-2025-6558Weaponized | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentiallgoogle · chrome · CWE-20 | High8.8 | KEV | 9.6% | Jul 15, 2025 |
65This week | CVE-2025-31277Weaponized | The issue was addressed with improved memory handling.apple · safari · CWE-119 | High8.8 | KEV | 1.6% | Jul 29, 2025 |
65This week | CVE-2019-8720Weaponized | A vulnerability was found in WebKit.webkitgtk · webkitgtk · CWE-119 | High8.8 | KEV | 1.6% | Mar 6, 2023 |
63This week | CVE-2021-30952Weaponized | An integer overflow was addressed with improved input validation.apple · safari · CWE-190 | High7.8 | KEV | 7.0% | Aug 24, 2021 |
41Plan | CVE-2020-13753No exploit | The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl.webkitgtk · webkitgtk · CWE-20 | Critical10.0 | — | 3.3% | Jul 14, 2020 |
40Plan | CVE-2020-10018No exploit | WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-webkitgtk · webkitgtk · CWE-416 | Critical9.8 | — | 5.0% | Mar 2, 2020 |
40Plan | CVE-2023-40397No exploit | The issue was addressed with improved checks.apple · macos | Critical9.8 | — | 1.7% | Sep 6, 2023 |
39Monitor | CVE-2025-43343No exploit | The issue was addressed with improved memory handling.apple · safari · CWE-119 | Critical9.8 | — | 0.8% | Sep 15, 2025 |
39Monitor | CVE-2025-43342No exploit | A correctness issue was addressed with improved checks.apple · safari · CWE-20 | Critical9.8 | — | 0.7% | Sep 15, 2025 |
38Monitor | CVE-2018-12293Proof of concept | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitcanonical · ubuntu linux · CWE-190 | High8.8 | — | 10.4% | Jun 19, 2018 |
36Monitor | CVE-2020-11793No exploit | A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers twebkitgtk · webkitgtk · CWE-416 | High8.8 | — | 2.9% | Apr 17, 2020 |
35Monitor | CVE-2023-28198No exploit | A use-after-free issue was addressed with improved memory management.apple · ipados · CWE-416 | High8.8 | — | 0.9% | Aug 14, 2023 |
33Monitor | CVE-2019-6251No exploit | WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections.webkitgtk · webkitgtk | High8.1 | — | 4.1% | Jan 14, 2019 |
26Monitor | CVE-2024-23263No exploit | A logic issue was addressed with improved validation.apple · safari · CWE-20 | Medium6.5 | — | 1.5% | Mar 7, 2024 |
26Monitor | CVE-2024-23284No exploit | A logic issue was addressed with improved state management.apple · safari · CWE-693 | Medium6.5 | — | 1.5% | Mar 7, 2024 |
26Monitor | CVE-2024-23280No exploit | An injection issue was addressed with improved validation.apple · safari · CWE-74 | Medium6.5 | — | 1.3% | Mar 7, 2024 |
26Monitor | CVE-2024-23254No exploit | The issue was addressed with improved UI handling.apple · safari | Medium6.5 | — | 1.3% | Mar 7, 2024 |
22Monitor | CVE-2019-11070No exploit | WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (webkitgtk · webkitgtk · CWE-19 | Medium5.3 | — | 3.3% | Apr 10, 2019 |
22Monitor | CVE-2024-27834No exploit | The issue was addressed with improved checks.apple · safari · CWE-277 | Medium5.5 | — | 0.6% | May 14, 2024 |
21Monitor | CVE-2023-32370No exploit | A logic issue was addressed with improved validation.apple · macos | Medium5.3 | — | 0.8% | Sep 5, 2023 |
21Monitor | CVE-2021-42762No exploit | BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick howebkitgtk · webkitgtk | Medium5.3 | — | 0.5% | Oct 20, 2021 |
17Monitor | CVE-2023-42843No exploit | An inconsistent user interface issue was addressed with improved state management.apple · safari · CWE-290 | Medium4.3 | — | 0.9% | Feb 21, 2024 |
- CVE-2022-229486Now
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via
HighCVSS 8.8KEVWeaponizedEPSS 70%google · chromeJul 27, 2022
- CVE-2022-3289368This week
An out-of-bounds write issue was addressed with improved bounds checking.
HighCVSS 8.8KEVWeaponizedEPSS 10%apple · safariAug 24, 2022
- CVE-2025-655868This week
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentiall
HighCVSS 8.8KEVWeaponizedEPSS 10%google · chromeJul 15, 2025
- CVE-2025-3127765This week
The issue was addressed with improved memory handling.
HighCVSS 8.8KEVWeaponizedEPSS 2%apple · safariJul 29, 2025
- CVE-2019-872065This week
A vulnerability was found in WebKit.
HighCVSS 8.8KEVWeaponizedEPSS 2%webkitgtk · webkitgtkMar 6, 2023
- CVE-2021-3095263This week
An integer overflow was addressed with improved input validation.
HighCVSS 7.8KEVWeaponizedEPSS 7%apple · safariAug 24, 2021
- CVE-2020-1375341Plan
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl.
CriticalCVSS 10.0No exploitEPSS 3%webkitgtk · webkitgtkJul 14, 2020
- CVE-2020-1001840Plan
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-
CriticalCVSS 9.8No exploitEPSS 5%webkitgtk · webkitgtkMar 2, 2020
- CVE-2023-4039740Plan
The issue was addressed with improved checks.
CriticalCVSS 9.8No exploitEPSS 2%apple · macosSep 6, 2023
- CVE-2025-4334339Monitor
The issue was addressed with improved memory handling.
CriticalCVSS 9.8No exploitEPSS 1%apple · safariSep 15, 2025
- CVE-2025-4334239Monitor
A correctness issue was addressed with improved checks.
CriticalCVSS 9.8No exploitEPSS 1%apple · safariSep 15, 2025
- CVE-2018-1229338Monitor
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKit
HighCVSS 8.8Proof of conceptEPSS 10%canonical · ubuntu linuxJun 19, 2018
- CVE-2020-1179336Monitor
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers t
HighCVSS 8.8No exploitEPSS 3%webkitgtk · webkitgtkApr 17, 2020
- CVE-2023-2819835Monitor
A use-after-free issue was addressed with improved memory management.
HighCVSS 8.8No exploitEPSS 1%apple · ipadosAug 14, 2023
- CVE-2019-625133Monitor
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections.
HighCVSS 8.1No exploitEPSS 4%webkitgtk · webkitgtkJan 14, 2019
- CVE-2024-2326326Monitor
A logic issue was addressed with improved validation.
MediumCVSS 6.5No exploitEPSS 1%apple · safariMar 7, 2024
- CVE-2024-2328426Monitor
A logic issue was addressed with improved state management.
MediumCVSS 6.5No exploitEPSS 1%apple · safariMar 7, 2024
- CVE-2024-2328026Monitor
An injection issue was addressed with improved validation.
MediumCVSS 6.5No exploitEPSS 1%apple · safariMar 7, 2024
- CVE-2024-2325426Monitor
The issue was addressed with improved UI handling.
MediumCVSS 6.5No exploitEPSS 1%apple · safariMar 7, 2024
- CVE-2019-1107022Monitor
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (
MediumCVSS 5.3No exploitEPSS 3%webkitgtk · webkitgtkApr 10, 2019
- CVE-2024-2783422Monitor
The issue was addressed with improved checks.
MediumCVSS 5.5No exploitEPSS 1%apple · safariMay 14, 2024
- CVE-2023-3237021Monitor
A logic issue was addressed with improved validation.
MediumCVSS 5.3No exploitEPSS 1%apple · macosSep 5, 2023
- CVE-2021-4276221Monitor
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick ho
MediumCVSS 5.3No exploitEPSS 1%webkitgtk · webkitgtkOct 20, 2021
- CVE-2023-4284317Monitor
An inconsistent user interface issue was addressed with improved state management.
MediumCVSS 4.3No exploitEPSS 1%apple · safariFeb 21, 2024