Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Electron MEDIUM 5.6
CVE-2020-15215

Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `s…

Mitigation only
Fix from $1,600 2020-10-06
Electron CRITICAL 9.9
CVE-2020-4077

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…

Fix: 7.2.4 / 8.2.4+
Fix from $2,300 2020-07-07
Electron CRITICAL 9.0
CVE-2020-4076

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the render…

Fix: 7.2.4 / 8.2.4+
Fix from $2,300 2020-07-07
Electron HIGH 7.5
CVE-2020-4075

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window…

Fix: 7.2.4 / 8.2.4+
Fix from $1,950 2020-07-07
Electron MEDIUM 6.8
CVE-2020-15096

In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world c…

Fix: 6.1.1 / 7.2.4+
Fix from $1,600 2020-07-07
Electron HIGH 8.1
CVE-2018-15685EPSS 10%

GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true…

No fix yet
Fix from $1,950 2018-08-23
Electron CRITICAL 9.8
CVE-2017-16151

Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent …

Fix: 1.7.8+
Fix from $2,300 2018-06-07
Electron HIGH 8.1
CVE-2018-1000136EPSS 5%

Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews tha…

Fix: after 1.8.3
Fix from $1,950 2018-03-23
Electron HIGH 8.8
CVE-2018-1000118

Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command e…

Fix: after 1.8.1
Fix from $1,950 2018-03-07