Перейти к содержимому
Noroxi

Записи electronjs

40 опубликованных записей вендора electronjs.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
95 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

40 записей
  • CVE-2017-16151
    40В плане

    Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects al

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    electronjs · electron6 июн. 2018 г.

  • CVE-2022-29247
    39Наблюдать

    Exposure of Resource to Wrong Sphere in Electron

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    electronjs · electron13 июн. 2022 г.

  • CVE-2020-4077
    39Наблюдать

    Context isolation bypass via contextBridge in Electron

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    electronjs · electron6 июл. 2020 г.

  • CVE-2023-23623
    39Наблюдать

    Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    electronjs · electron6 сент. 2023 г.

  • CVE-2026-34775
    39Наблюдать

    Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2020-35717
    37Наблюдать

    zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)

    КритическаяCVSS 9,0Proof of conceptEPSS 4 %

    electronjs · zonote1 янв. 2021 г.

  • CVE-2018-1000118
    36Наблюдать

    Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    electronjs · electron7 мар. 2018 г.

  • CVE-2021-32772
    36Наблюдать

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entries

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    electronjs · poddycast3 авг. 2021 г.

  • CVE-2020-4076
    36Наблюдать

    Context isolation bypass via leaked cross-context objects in Electron

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    electronjs · electron6 июл. 2020 г.

  • CVE-2018-15685
    35Наблюдать

    GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sand

    ВысокаяCVSS 8,1Proof of conceptEPSS 10 %

    electronjs · electron23 авг. 2018 г.

  • CVE-2026-34769
    35Наблюдать

    Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2026-34771
    35Наблюдать

    Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2026-34765
    35Наблюдать

    Electron named window.open targets not scoped to the opener's browsing context

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    electronjs · electron7 апр. 2026 г.

  • CVE-2026-34770
    35Наблюдать

    Electron: Use-after-free in PowerMonitor on Windows and macOS

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2026-34772
    35Наблюдать

    Electron: Use-after-free in download save dialog callback

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2018-1000136
    34Наблюдать

    Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Web

    ВысокаяCVSS 8,1Эксплойта нетEPSS 5 %

    electronjs · electron23 мар. 2018 г.

  • CVE-2021-39184
    34Наблюдать

    Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    electronjs · electron12 окт. 2021 г.

  • CVE-2023-29198
    34Наблюдать

    Context isolation bypass via nested unserializable return value in Electron

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    electronjs · electron6 сент. 2023 г.

  • CVE-2026-34774
    32Наблюдать

    Electron: Use-after-free in offscreen child window paint callback

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2026-34779
    31Наблюдать

    Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2026-34768
    31Наблюдать

    Electron: Unquoted executable path in app.setLoginItemSettings on Windows

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2020-15174
    30Наблюдать

    Unpreventable top-level navigation in Electron

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    electronjs · electron6 окт. 2020 г.

  • CVE-2020-4075
    30Наблюдать

    Arbitrary file read via window-open IPC in Electron

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    electronjs · electron6 июл. 2020 г.

  • CVE-2026-34773
    30Наблюдать

    Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2022-29257
    28Наблюдать

    Electron's AutoUpdater module fails to validate certain nested components of the bundle

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    electronjs · electron13 июн. 2022 г.