LINE Corporation
First CVE: Jul 13, 2021Active for: 5 years
23
CVEs Published
More CVEs Published than 44% of tracked CNAs
3.8
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 32% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by LINE Corporation as a CNA, 0.0% affect products that LINE Corporation develops as a vendor.
100.0%
Self-reported: 0Third-party: 23
Of all the CVEs published that affect products developed by LINE Corporation, 0.0% are self-published by LINE Corporation as a CNA.
100.0%
Self-published: 0Published by other CNAs: 3
Trends Over Time
The number and severity of CVEs published by LINE Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 13, 2021
5 years ago
Most Recent CVE
Jun 22, 2026
33 days ago
Top CVEs
All CVEs published by LINE Corporation as a CNA, regardless of affected vendor or product.
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11746CRITICAL A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to si | Jun 22, 2026 | 9.4 | 32 | NO | NO |
CVE-2026-11745HIGH A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// conn | Jun 22, 2026 | 8.8 | 31 | NO | NO |
CVE-2023-5554CRITICAL Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0. | Oct 12, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-38388HIGH Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. | Sep 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-11748MEDIUM A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDA | Jun 22, 2026 | 6.9 | 26 | NO | NO |
CVE-2026-3861MEDIUM LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insuffic | Apr 16, 2026 | 6.5 | 26 | NO | NO |
CVE-2022-29505HIGH Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation. | Apr 27, 2022 | 7.8 | 26 | NO | NO |
CVE-2026-11752MEDIUM A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environ | Jun 19, 2026 | 5.9 | 25 | NO | NO |
CVE-2022-41568HIGH LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. | Nov 29, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-36216HIGH LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection. | Sep 8, 2021 | 7.8 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA23 CVEs
61%
26%
13%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (13.0%)
Network17 (73.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.3%)
Attack Complexity
Low21 (91.3%)
High2 (8.7%)
Unknown0 (0.0%)
User Interaction
None12 (52.2%)
Unknown0 (0.0%)
Required11 (47.8%)
Privileges Required
Low2 (8.7%)
High1 (4.3%)
None20 (87.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by LINE Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by LINE Corporation as a CNA — matched by CVE ID, not by organization name.