Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
Showing 21 - 40 of 417 CVEs
CVE-2026-34779 MEDIUM - 6.5

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the appli...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34778 MEDIUM - 5.9

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and relat...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34777 MEDIUM - 5.4

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionR...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34776 MEDIUM - 5.3

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34775 MEDIUM - 6.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawne...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34774 HIGH - 8.1

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34773 MEDIUM - 4.7

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrust...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34772 MEDIUM - 5.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while ...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34771 HIGH - 7.5

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34770 HIGH - 7.0

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected,...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34769 HIGH - 7.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps ...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the app...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34767 MEDIUM - 5.9

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via webR...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler....

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-32929 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32928 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32927 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32926 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-32925 HIGH - 7.8

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Vendor: FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd.
Product: V-SFT
Published: Apr 01, 2026
Source: NVD
CVE-2026-34725 HIGH - 8.3

DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in...

Vendor: npm
Product: dbgate-web
Published: Apr 01, 2026
Source: GitHub