Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Billboard.js MEDIUM 6.1
CVE-2026-1513

billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.

Fix: 3.18.0+
Fix from $1,600 2026-01-28
Lucy Xss Filter MEDIUM 6.1
CVE-2026-23768

lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or Emb…

Fix: 2025-06-08+
Fix from $1,600 2026-01-16
Lucy Xss Filter MEDIUM 6.1
CVE-2026-23769

lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigured default…

Fix: 2025-06-08+
Fix from $1,600 2026-01-16
Billboard.js CRITICAL 9.8
CVE-2025-49223

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrar…

Fix: 3.15.1+
Fix from $2,300 2025-06-04
Ngrinder MEDIUM 5.4
CVE-2024-28216

nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of informa…

Fix: 3.5.9+
Fix from $1,600 2024-03-07
Ngrinder CRITICAL 9.8
CVE-2024-28211

nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry…

Fix: 3.5.9+
Fix from $2,300 2024-03-07
Ngrinder CRITICAL 9.8
CVE-2024-28212

nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

Fix: 3.5.9+
Fix from $2,300 2024-03-07
Ngrinder CRITICAL 9.8
CVE-2024-28213

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary cod…

Fix: 3.5.9+
Fix from $2,300 2024-03-07
Ngrinder HIGH 7.5
CVE-2024-28215

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of informa…

Fix: 3.5.9+
Fix from $1,950 2024-03-07
Whale Browser MEDIUM 5.5
CVE-2023-25632

The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.

Fix: 3.0.1.2+
Fix from $1,600 2023-11-27
Cloud Explorer HIGH 7.8
CVE-2022-24077

Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

Mitigation only
Fix from $1,950 2022-06-13
Toolbar CRITICAL 9.8
CVE-2021-33592

NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename para…

Fix: 4.0.30.323+
Fix from $2,300 2021-07-19
Comic Viewer HIGH 8.8
CVE-2021-33591

An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Fix: 1.0.15.0+
Fix from $1,950 2021-05-28
Whale Browser Installer CRITICAL 9.1
CVE-2020-9753

Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

Fix: 2.6.88.19+
Fix from $2,300 2020-05-20
Cloud Explorer CRITICAL 9.8
CVE-2020-9752

Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named …

Fix: 2.2.2.11+
Fix from $2,300 2020-03-23
Cloud Explorer CRITICAL 9.1
CVE-2020-9751

Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.

Fix: 2.2.2.11+
Fix from $2,300 2020-03-03
Vaccine HIGH 7.5
CVE-2019-13157

nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz arc…

Mitigation only
Fix from $1,950 2019-11-22
Cloud Explorer HIGH 7.5
CVE-2019-13156

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data fr…

Mitigation only
Fix from $1,950 2019-09-03
Ngrinder MEDIUM 6.1
CVE-2016-5060

Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) …

Fix: after 3.3
Fix from $1,600 2016-12-13
Line Play MEDIUM 5.4
CVE-2014-6980

The LINE PLAY (aka jp.naver.lineplay.android) application 2.3.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-i…

Mitigation only
Fix from $1,600 2014-10-16
Nhn Japan Naver Line MEDIUM 5.0
CVE-2012-4005

The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obtain sens…

Fix: after 2.5
Fix from $1,600 2012-08-07