彙總 nwjs 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
已披露問題常與 輸入驗證問題 相關,可能在 生產負載與軟體部署 場景中帶來 異常行為 等暴露風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2014-9530 | A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact. | [email protected] | 9.8 | 1.16% | 2020-02-07 | 2026-06-16 |
| CVE-2016-10588 | nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server. | [email protected] | 8.1 | 1.76% | 2018-06-01 | 2026-06-16 |
| CVE-2014-9733 | nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified impact via unknown vectors. | [email protected] | 9.8 | 1.39% | 2017-10-17 | 2026-06-16 |