Vulnerabilities
44 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8148 | NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improp NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-1513 | billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding. billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2026-23768 +1 in the same advisory: …23769 | lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityL lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-69234 +1 in the same advisory: …69235 | Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment. Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2025-62583 | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-58323 | NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to impr NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks. NVD description · AI analysis pending | 7.7 | <1% |
| — | ||
| CVE-2025-58322 | NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improp NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-53599 +1 in the same advisory: …53600 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-49223 | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or c billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-13330 | The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2024-28213 | nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsaf nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2023-25632 | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature. The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-0146 | The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-9754 | NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode. NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2022-24077 | Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection. Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2022-24074 | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2022-24071 | A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal A A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2021-33593 | Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2021-33592 | NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-33591 | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page. An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2020-9753 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. NVD description · AI analysis pending | 9.1 | 1% |
| — | ||
| CVE-2020-9752 | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe. Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-9751 | Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade. Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade. NVD description · AI analysis pending | 9.1 | <1% |
| — | ||
| CVE-2019-13157 | nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive. nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2019-13156 | NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL ha NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2018-12449 | The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2018-12448 | Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allow Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2018-7635 | Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows a Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2018-9859 | The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2017-15913 | The Installer in Whale allows DLL hijacking. The Installer in Whale allows DLL hijacking. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2016-5060 | Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description, (2) email, or (3) username parameter to user/save. NVD description · AI analysis pending | 6.1 | 2% |
| — |