6.5

CVSS3.1

CVE-2026-3571 - Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization…

The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attacke…

📅 Published: April 4, 2026, 1:24 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

9.1

CVSS3.1

CVE-2026-35616 - Unauthenticated Remote Code Execution in FortiClientEMS 7.4.5-7.4.6

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

📅 Published: April 4, 2026, 12:38 a.m. 🔄 Last Modified: April 7, 2026, 3:58 p.m.

8.4

CVSS3.1

CVE-2026-34780 - Electron: Context Isolation bypass via contextBridge VideoFrame transfer

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the c…

📅 Published: April 4, 2026, 12:02 a.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

6.5

CVSS3.1

CVE-2026-34779 - Electron: AppleScript injection in app.moveToApplicationsFolder on macOS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the appl…

📅 Published: April 4, 2026, midnight 🔄 Last Modified: April 8, 2026, 3:55 a.m.

5.9

CVSS3.1

CVE-2026-34778 - Electron: Service worker can spoof executeJavaScript IPC replies

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and rela…

📅 Published: April 3, 2026, 11:59 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.4

CVSS3.1

CVE-2026-34777 - Electron: Incorrect origin passed to permission request handler for iframe requests

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermission…

📅 Published: April 3, 2026, 11:57 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS3.1

CVE-2026-34776 - Electron: Out-of-bounds read in second-instance IPC on macOS and Linux

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted secon…

📅 Published: April 3, 2026, 11:56 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

6.8

CVSS3.1

CVE-2026-34775 - Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawn…

📅 Published: April 3, 2026, 11:55 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

8.1

CVSS3.1

CVE-2026-34774 - Electron: Use-after-free in offscreen child window paint callback

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContent…

📅 Published: April 3, 2026, 11:52 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

4.7

CVSS3.1

CVE-2026-34773 - Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrus…

📅 Published: April 3, 2026, 11:50 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343921
Page 172 of 34,393
« previous page » next page
Filters