electronjs kayıtları
electronjs üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %95
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-668 Exposure of Resource to Wrong Sphere7
- CWE-416 Use After Free5
- CWE-20 Improper Input Validation4
- CWE-501 Trust Boundary Violation3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-16151İstismar yok | Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects alelectronjs · electron · CWE-94 | Kritik9,8 | — | %2,7 | 6 Haz 2018 |
39İzleyin | CVE-2022-29247İstismar yok | Exposure of Resource to Wrong Sphere in Electronelectronjs · electron · CWE-668 | Kritik9,8 | — | %1,0 | 13 Haz 2022 |
39İzleyin | CVE-2020-4077İstismar yok | Context isolation bypass via contextBridge in Electronelectronjs · electron · CWE-501 | Kritik9,9 | — | %1,0 | 6 Tem 2020 |
39İzleyin | CVE-2023-23623İstismar yok | Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electronelectronjs · electron · CWE-670 | Kritik9,8 | — | %0,7 | 6 Eyl 2023 |
39İzleyin | CVE-2026-34775İstismar yok | Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processeselectronjs · electron · CWE-653 | Kritik9,8 | — | %0,4 | 3 Nis 2026 |
37İzleyin | CVE-2020-35717Kavram kanıtı | zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)electronjs · zonote · CWE-79 | Kritik9,0 | — | %3,8 | 1 Oca 2021 |
36İzleyin | CVE-2018-1000118İstismar yok | Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in electronjs · electron · CWE-78 | Yüksek8,8 | — | %2,4 | 7 Mar 2018 |
36İzleyin | CVE-2021-32772İstismar yok | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entrieselectronjs · poddycast · CWE-78 | Yüksek8,8 | — | %2,4 | 3 Ağu 2021 |
36İzleyin | CVE-2020-4076İstismar yok | Context isolation bypass via leaked cross-context objects in Electronelectronjs · electron · CWE-501 | Kritik9,0 | — | %0,4 | 6 Tem 2020 |
35İzleyin | CVE-2018-15685Kavram kanıtı | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandelectronjs · electron · CWE-1188 | Yüksek8,1 | — | %10,4 | 23 Ağu 2018 |
35İzleyin | CVE-2026-34769İstismar yok | Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreferenceelectronjs · electron · CWE-88 | Yüksek8,8 | — | %0,4 | 3 Nis 2026 |
35İzleyin | CVE-2026-34771İstismar yok | Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbackselectronjs · electron · CWE-416 | Yüksek8,8 | — | %0,4 | 3 Nis 2026 |
35İzleyin | CVE-2026-34765İstismar yok | Electron named window.open targets not scoped to the opener's browsing contextelectronjs · electron · CWE-668 | Yüksek8,8 | — | %0,4 | 7 Nis 2026 |
35İzleyin | CVE-2026-34770İstismar yok | Electron: Use-after-free in PowerMonitor on Windows and macOSelectronjs · electron · CWE-416 | Yüksek8,8 | — | %0,3 | 3 Nis 2026 |
35İzleyin | CVE-2026-34772İstismar yok | Electron: Use-after-free in download save dialog callbackelectronjs · electron · CWE-416 | Yüksek8,8 | — | %0,2 | 3 Nis 2026 |
34İzleyin | CVE-2018-1000136İstismar yok | Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webelectronjs · electron · CWE-20 | Yüksek8,1 | — | %5,1 | 23 Mar 2018 |
34İzleyin | CVE-2021-39184İstismar yok | Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIelectronjs · electron · CWE-668 | Yüksek8,6 | — | %1,1 | 12 Eki 2021 |
34İzleyin | CVE-2023-29198İstismar yok | Context isolation bypass via nested unserializable return value in Electronelectronjs · electron · CWE-754 | Yüksek8,5 | — | %0,6 | 6 Eyl 2023 |
32İzleyin | CVE-2026-34774İstismar yok | Electron: Use-after-free in offscreen child window paint callbackelectronjs · electron · CWE-416 | Yüksek8,1 | — | %0,6 | 3 Nis 2026 |
31İzleyin | CVE-2026-34779İstismar yok | Electron: AppleScript injection in app.moveToApplicationsFolder on macOSelectronjs · electron · CWE-78 | Yüksek7,8 | — | %0,2 | 3 Nis 2026 |
31İzleyin | CVE-2026-34768İstismar yok | Electron: Unquoted executable path in app.setLoginItemSettings on Windowselectronjs · electron · CWE-428 | Yüksek7,8 | — | %0,1 | 3 Nis 2026 |
30İzleyin | CVE-2020-15174İstismar yok | Unpreventable top-level navigation in Electronelectronjs · electron · CWE-20 | Yüksek7,5 | — | %1,4 | 6 Eki 2020 |
30İzleyin | CVE-2020-4075İstismar yok | Arbitrary file read via window-open IPC in Electronelectronjs · electron · CWE-552 | Yüksek7,5 | — | %1,2 | 6 Tem 2020 |
30İzleyin | CVE-2026-34773İstismar yok | Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windowselectronjs · electron · CWE-20 | Yüksek7,5 | — | %0,3 | 3 Nis 2026 |
28İzleyin | CVE-2022-29257İstismar yok | Electron's AutoUpdater module fails to validate certain nested components of the bundleelectronjs · electron · CWE-20 | Yüksek7,2 | — | %0,9 | 13 Haz 2022 |
- CVE-2017-1615140Planlayın
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects al
KritikCVSS 9,8İstismar yokEPSS %3electronjs · electron6 Haz 2018
- CVE-2022-2924739İzleyin
Exposure of Resource to Wrong Sphere in Electron
KritikCVSS 9,8İstismar yokEPSS %1electronjs · electron13 Haz 2022
- CVE-2020-407739İzleyin
Context isolation bypass via contextBridge in Electron
KritikCVSS 9,9İstismar yokEPSS %1electronjs · electron6 Tem 2020
- CVE-2023-2362339İzleyin
Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron
KritikCVSS 9,8İstismar yokEPSS %1electronjs · electron6 Eyl 2023
- CVE-2026-3477539İzleyin
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
KritikCVSS 9,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2020-3571737İzleyin
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)
KritikCVSS 9,0Kavram kanıtıEPSS %4electronjs · zonote1 Oca 2021
- CVE-2018-100011836İzleyin
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in
YüksekCVSS 8,8İstismar yokEPSS %2electronjs · electron7 Mar 2018
- CVE-2021-3277236İzleyin
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entries
YüksekCVSS 8,8İstismar yokEPSS %2electronjs · poddycast3 Ağu 2021
- CVE-2020-407636İzleyin
Context isolation bypass via leaked cross-context objects in Electron
KritikCVSS 9,0İstismar yokEPSS %0electronjs · electron6 Tem 2020
- CVE-2018-1568535İzleyin
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sand
YüksekCVSS 8,1Kavram kanıtıEPSS %10electronjs · electron23 Ağu 2018
- CVE-2026-3476935İzleyin
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
YüksekCVSS 8,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2026-3477135İzleyin
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
YüksekCVSS 8,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2026-3476535İzleyin
Electron named window.open targets not scoped to the opener's browsing context
YüksekCVSS 8,8İstismar yokEPSS %0electronjs · electron7 Nis 2026
- CVE-2026-3477035İzleyin
Electron: Use-after-free in PowerMonitor on Windows and macOS
YüksekCVSS 8,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2026-3477235İzleyin
Electron: Use-after-free in download save dialog callback
YüksekCVSS 8,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2018-100013634İzleyin
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Web
YüksekCVSS 8,1İstismar yokEPSS %5electronjs · electron23 Mar 2018
- CVE-2021-3918434İzleyin
Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
YüksekCVSS 8,6İstismar yokEPSS %1electronjs · electron12 Eki 2021
- CVE-2023-2919834İzleyin
Context isolation bypass via nested unserializable return value in Electron
YüksekCVSS 8,5İstismar yokEPSS %1electronjs · electron6 Eyl 2023
- CVE-2026-3477432İzleyin
Electron: Use-after-free in offscreen child window paint callback
YüksekCVSS 8,1İstismar yokEPSS %1electronjs · electron3 Nis 2026
- CVE-2026-3477931İzleyin
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
YüksekCVSS 7,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2026-3476831İzleyin
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
YüksekCVSS 7,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2020-1517430İzleyin
Unpreventable top-level navigation in Electron
YüksekCVSS 7,5İstismar yokEPSS %1electronjs · electron6 Eki 2020
- CVE-2020-407530İzleyin
Arbitrary file read via window-open IPC in Electron
YüksekCVSS 7,5İstismar yokEPSS %1electronjs · electron6 Tem 2020
- CVE-2026-3477330İzleyin
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
YüksekCVSS 7,5İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2022-2925728İzleyin
Electron's AutoUpdater module fails to validate certain nested components of the bundle
YüksekCVSS 7,2İstismar yokEPSS %1electronjs · electron13 Haz 2022