ZeroHour

Vulnerabilities

44 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-8148
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improp

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

NVD description · AI analysis pending
7.8<1%
  • navercorp mybox
CVE-2026-1513
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.

billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.

NVD description · AI analysis pending
6.1<1%
  • naver billboard.js
CVE-2026-23768
+1 in the same advisory: …23769
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityL

lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension.

NVD description · AI analysis pending
6.1<1% PoC
  • naver lucy-xss-filter
CVE-2025-69234
+1 in the same advisory: …69235
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

NVD description · AI analysis pending
9.1
group max
<1%
  • navercorp whale
CVE-2025-62583
+2 in the same advisory: …62585 …62584
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

NVD description · AI analysis pending
9.8
group max
<1%
  • navercorp whale
CVE-2025-58323
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to impr

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks.

NVD description · AI analysis pending
7.7<1%
  • navercorp mybox
CVE-2025-58322
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improp

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks.

NVD description · AI analysis pending
7.8<1%
  • navercorp mybox
CVE-2025-53599
+1 in the same advisory: …53600
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

NVD description · AI analysis pending
9.8
group max
<1%
  • navercorp whale
CVE-2025-49223
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or c

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

NVD description · AI analysis pending
9.8<1%
  • naver billboard.js
CVE-2024-13330
The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

NVD description · AI analysis pending
7.1<1% PoC
  • canaveralstudio justrows free
CVE-2024-28213
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsaf

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.

NVD description · AI analysis pending
9.8
group max
1%
  • naver ngrinder
CVE-2023-25632
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.

The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.

NVD description · AI analysis pending
5.5<1%
  • naver whale browser
CVE-2023-0146
The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the

The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

NVD description · AI analysis pending
5.4<1% PoC
  • naver map project naver map
CVE-2020-9754
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.

NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.

NVD description · AI analysis pending
5.3<1%
  • navercorp whale
CVE-2022-24077
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

NVD description · AI analysis pending
7.8<1%
  • naver cloud explorer
CVE-2022-24074
+3 in the same advisory: …24073 …24075 …24072
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.

NVD description · AI analysis pending
9.8
group max
1%
  • navercorp whale
CVE-2022-24071
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal A

A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs.

NVD description · AI analysis pending
4.3<1%
  • navercorp whale
CVE-2021-33593
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar

Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.

NVD description · AI analysis pending
5.3<1%
  • navercorp whale
CVE-2021-33592
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file.

NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.

NVD description · AI analysis pending
9.82%
  • naver toolbar
CVE-2021-33591
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

NVD description · AI analysis pending
8.82%
  • naver comic viewer
CVE-2020-9753
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

NVD description · AI analysis pending
9.11%
  • naver whale browser installer
CVE-2020-9752
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.

Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.

NVD description · AI analysis pending
9.81%
  • naver cloud explorer
CVE-2020-9751
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.

Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.

NVD description · AI analysis pending
9.1<1%
  • naver cloud explorer
CVE-2019-13157
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.

nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.

NVD description · AI analysis pending
7.52%
  • naver vaccine
CVE-2019-13156
NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL ha

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.

NVD description · AI analysis pending
7.51%
  • naver cloud explorer
CVE-2018-12449
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.

The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.

NVD description · AI analysis pending
7.8<1%
  • navercorp whale
CVE-2018-12448
Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allow

Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name.

NVD description · AI analysis pending
5.3<1%
  • navercorp whale
CVE-2018-7635
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows a

Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name.

NVD description · AI analysis pending
5.3<1%
  • navercorp whale
CVE-2018-9859
The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7.

The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications.

NVD description · AI analysis pending
8.1<1%
  • navercorp whale
CVE-2017-15913
The Installer in Whale allows DLL hijacking.

The Installer in Whale allows DLL hijacking.

NVD description · AI analysis pending
7.81%
  • navercorp whale
CVE-2016-5060
Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description

Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description, (2) email, or (3) username parameter to user/save.

NVD description · AI analysis pending
6.12%
  • naver ngrinder