İçeriğe atla
Noroxi

electronjs kayıtları

electronjs üreticisine ait 40 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
5
Düzeltme kaydı olan
%95
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

40 kayıt
  • CVE-2017-16151
    40Planlayın

    Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects al

    KritikCVSS 9,8İstismar yokEPSS %3

    electronjs · electron6 Haz 2018

  • CVE-2022-29247
    39İzleyin

    Exposure of Resource to Wrong Sphere in Electron

    KritikCVSS 9,8İstismar yokEPSS %1

    electronjs · electron13 Haz 2022

  • CVE-2020-4077
    39İzleyin

    Context isolation bypass via contextBridge in Electron

    KritikCVSS 9,9İstismar yokEPSS %1

    electronjs · electron6 Tem 2020

  • CVE-2023-23623
    39İzleyin

    Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in Electron

    KritikCVSS 9,8İstismar yokEPSS %1

    electronjs · electron6 Eyl 2023

  • CVE-2026-34775
    39İzleyin

    Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

    KritikCVSS 9,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2020-35717
    37İzleyin

    zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true)

    KritikCVSS 9,0Kavram kanıtıEPSS %4

    electronjs · zonote1 Oca 2021

  • Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in

    YüksekCVSS 8,8İstismar yokEPSS %2

    electronjs · electron7 Mar 2018

  • CVE-2021-32772
    36İzleyin

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entries

    YüksekCVSS 8,8İstismar yokEPSS %2

    electronjs · poddycast3 Ağu 2021

  • CVE-2020-4076
    36İzleyin

    Context isolation bypass via leaked cross-context objects in Electron

    KritikCVSS 9,0İstismar yokEPSS %0

    electronjs · electron6 Tem 2020

  • CVE-2018-15685
    35İzleyin

    GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sand

    YüksekCVSS 8,1Kavram kanıtıEPSS %10

    electronjs · electron23 Ağu 2018

  • CVE-2026-34769
    35İzleyin

    Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

    YüksekCVSS 8,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2026-34771
    35İzleyin

    Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks

    YüksekCVSS 8,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2026-34765
    35İzleyin

    Electron named window.open targets not scoped to the opener's browsing context

    YüksekCVSS 8,8İstismar yokEPSS %0

    electronjs · electron7 Nis 2026

  • CVE-2026-34770
    35İzleyin

    Electron: Use-after-free in PowerMonitor on Windows and macOS

    YüksekCVSS 8,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2026-34772
    35İzleyin

    Electron: Use-after-free in download save dialog callback

    YüksekCVSS 8,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Web

    YüksekCVSS 8,1İstismar yokEPSS %5

    electronjs · electron23 Mar 2018

  • CVE-2021-39184
    34İzleyin

    Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API

    YüksekCVSS 8,6İstismar yokEPSS %1

    electronjs · electron12 Eki 2021

  • CVE-2023-29198
    34İzleyin

    Context isolation bypass via nested unserializable return value in Electron

    YüksekCVSS 8,5İstismar yokEPSS %1

    electronjs · electron6 Eyl 2023

  • CVE-2026-34774
    32İzleyin

    Electron: Use-after-free in offscreen child window paint callback

    YüksekCVSS 8,1İstismar yokEPSS %1

    electronjs · electron3 Nis 2026

  • CVE-2026-34779
    31İzleyin

    Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

    YüksekCVSS 7,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2026-34768
    31İzleyin

    Electron: Unquoted executable path in app.setLoginItemSettings on Windows

    YüksekCVSS 7,8İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2020-15174
    30İzleyin

    Unpreventable top-level navigation in Electron

    YüksekCVSS 7,5İstismar yokEPSS %1

    electronjs · electron6 Eki 2020

  • CVE-2020-4075
    30İzleyin

    Arbitrary file read via window-open IPC in Electron

    YüksekCVSS 7,5İstismar yokEPSS %1

    electronjs · electron6 Tem 2020

  • CVE-2026-34773
    30İzleyin

    Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

    YüksekCVSS 7,5İstismar yokEPSS %0

    electronjs · electron3 Nis 2026

  • CVE-2022-29257
    28İzleyin

    Electron's AutoUpdater module fails to validate certain nested components of the bundle

    YüksekCVSS 7,2İstismar yokEPSS %1

    electronjs · electron13 Haz 2022