Vulnerabilidades em electron
55 resultadosAnálise Vexday
Electron apresenta 39 vulnerabilidades catalogadas com apenas 1 crítica, e nenhuma sob exploração ativa conhecida, indicando risco contido. A fraqueza predominante é relacionada a exposição inadequada de funcionalidades (CWE-668), padrão esperado para uma plataforma de execução. Apenas 1 vulnerabilidade publicada nos últimos 90 dias sugere que o risco atual é estável, sem sinais recentes de degradação.
CVE-2020-26272MEDIUMElectron vulnerable to ID collision when routing IPC messages to renderers containing OOPIFsEPSS 1.7%CVE-2020-15174HIGHUnpreventable top-level navigation in ElectronEPSS 1.4%CVE-2020-4075MEDIUMArbitrary file read via window-open IPC in ElectronEPSS 1.2%CVE-2021-39184MEDIUMSandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIEPSS 1.1%CVE-2020-4077HIGHContext isolation bypass via contextBridge in ElectronEPSS 1.0%CVE-2022-29247LOWExposure of Resource to Wrong Sphere in ElectronEPSS 1.0%CVE-2022-21718LOWRenderers can obtain access to random bluetooth device without permission in ElectronEPSS 0.9%CVE-2022-29257MEDIUMElectron's AutoUpdater module fails to validate certain nested components of the bundleEPSS 0.9%CVE-2020-15096MEDIUMContext isolation bypass via Promise in ElectronEPSS 0.8%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2023-23623HIGHContent-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in ElectronEPSS 0.7%CVE-2024-29900HIGH@electron/packager's build process memory potentially leaked into final executableEPSS 0.6%CVE-2023-39956MEDIUMElectron: Out-of-package code execution when launched with arbitrary cwdEPSS 0.6%CVE-2022-36077HIGHElectron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirectEPSS 0.5%CVE-2023-29198MEDIUMContext isolation bypass via nested unserializable return value in ElectronEPSS 0.5%CVE-2026-34774HIGHElectron: Use-after-free in offscreen child window paint callbackEPSS 0.4%CVE-2026-70610MEDIUMElectron: contextBridge object copy honors prototype settersEPSS 0.4%CVE-2020-4076HIGHContext isolation bypass via leaked cross-context objects in ElectronEPSS 0.4%CVE-2026-70612MEDIUMElectron: Sandboxed iframes can launch external protocol handlersEPSS 0.4%CVE-2026-70607MEDIUMElectron: window.open features string controls some window options considered privilegedEPSS 0.3%