Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-8148
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation du…
Mybox
3.0.11.160+
CRITICAL 9.1
CVE-2025-69234
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
Whale
4.35.351.12+
HIGH 7.5
CVE-2025-69235
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
Whale
4.35.351.12+
CRITICAL 9.8
CVE-2025-62583
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
Whale
4.33.325.17+
HIGH 7.5
CVE-2025-62584
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
Whale
4.33.325.17+
HIGH 7.5
CVE-2025-62585
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
Whale
4.33.325.17+
HIGH 7.7
CVE-2025-58323
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files …
Mybox
3.0.8.133+
HIGH 7.8
CVE-2025-58322
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs du…
Mybox
3.0.8.133+
CRITICAL 9.8
CVE-2025-53599
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
Whale
3.9.1.4206+
HIGH 7.5
CVE-2025-53600
Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
Whale
4.32.315.22+
MEDIUM 5.3
CVE-2020-9754
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.
Whale
1.10.6.2+
CRITICAL 9.8
CVE-2022-24074
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that…
Whale
3.12.129.18+
HIGH 7.1
CVE-2022-24073
The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the st…
Whale
3.12.129.18+
MEDIUM 6.5
CVE-2022-24075
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When…
Whale
3.12.129.18+
MEDIUM 6.1
CVE-2022-24072
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page vi…
Whale
3.12.129.18+
MEDIUM 5.3
CVE-2021-33593
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to a…
Whale
1.14.0+
HIGH 7.8
CVE-2018-12449
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
Whale
after 0.4.3.0
MEDIUM 5.3
CVE-2018-12448
Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, …
Whale
1.3.48.4+
MEDIUM 5.3
CVE-2018-7635
Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, whi…
Whale
1.0.41.8+
HIGH 8.1
CVE-2018-9859
The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if i…
Whale
1.0.40.7+
HIGH 7.8
CVE-2017-15913
The Installer in Whale allows DLL hijacking.
Whale
No fix yet