← Back

Proton

proton

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Protonvpn
protonvpn

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Proton
1Protonvpn
Mar 2, 2026
Jan 13, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placin...Show more
ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during service startup.Show less
1Proton
1Protonvpn
Mar 13, 2025
Jul 22, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.
1Proton
1Energymech Irc Bot
Apr 16, 2026
Jun 29, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parse_notice (TiCPU) in EnergyMech (emech) before 3.0.2 allows remote attackers to cause a denial of service (crash) via empty IRC CTCP NOTICE messages.