8.1

CVSS3.1

CVE-2026-34774 - Electron: Use-after-free in offscreen child window paint callback

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContent…

📅 Published: April 3, 2026, 11:52 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

4.7

CVSS3.1

CVE-2026-34773 - Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrus…

📅 Published: April 3, 2026, 11:50 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.8

CVSS3.1

CVE-2026-34772 - Electron: Use-after-free in download save dialog callback

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while…

📅 Published: April 3, 2026, 11:49 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

7.5

CVSS3.1

CVE-2026-34771 - Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission call…

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscree…

📅 Published: April 3, 2026, 11:47 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

7

CVSS3.1

CVE-2026-34770 - Electron: Use-after-free in PowerMonitor on Windows and macOS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected…

📅 Published: April 3, 2026, 11:46 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

3.9

CVSS3.1

CVE-2026-34768 - Electron: Unquoted executable path in app.setLoginItemSettings on Windows

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the ap…

📅 Published: April 3, 2026, 11:44 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

5.9

CVSS3.1

CVE-2026-34767 - Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via web…

📅 Published: April 3, 2026, 11:43 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

3.3

CVSS3.1

CVE-2026-34766 - Electron: USB device selection not validated against filtered device list

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler…

📅 Published: April 3, 2026, 11:35 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

7.8

CVSS3.1

CVE-2026-34769 - Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps…

📅 Published: April 3, 2026, 11:33 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

8.8

CVSS3.1

CVE-2026-34955 - PraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-pattern matching to block dangerous commands. The blocklist does not include sh or bash as standalone…

📅 Published: April 3, 2026, 11:04 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343923
Page 173 of 34,393
« previous page » next page
Filters