NwjsCVEs & Vulnerabilities
3 CVEs affecting Nwjs products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
nw 2nw.js 1
CVE-2014-9530CRITICAL
A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact.
7 Feb 2020
9.8
CVSS
CVE-2016-10588HIGH
nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
1 Jun 2018
8.1
CVSS
CVE-2014-9733CRITICAL
nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified impact via unknown vectors.
17 Oct 2017
9.8
CVSS
← PrevPage 1 / 1Next →