Naver Corporation
First CVE: Aug 2, 2018Active for: 8 years
40
CVEs Published
More CVEs Published than 53% of tracked CNAs
4.4
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Naver Corporation as a CNA, 47.5% affect products that Naver Corporation develops as a vendor.
47.5%
52.5%
Self-reported: 19Third-party: 21
Of all the CVEs published that affect products developed by Naver Corporation, 79.2% are self-published by Naver Corporation as a CNA.
79.2%
20.8%
Self-published: 19Published by other CNAs: 5
Trends Over Time
The number and severity of CVEs published by Naver Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2018
7 years ago
Most Recent CVE
May 8, 2026
77 days ago
Top CVEs
All CVEs published by Naver Corporation as a CNA, regardless of affected vendor or product.
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33592CRITICAL NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypas | Jul 19, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-8148HIGH NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. | May 8, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-62583CRITICAL Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. | Oct 16, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-49223CRITICAL billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Ser | Jun 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-28212CRITICAL nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization. | Mar 7, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-24074CRITICAL Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whal | Mar 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-9752CRITICAL Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe. | Mar 23, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-9753CRITICAL Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. | May 20, 2020 | 9.1 | 28 | NO | NO |
CVE-2020-9751CRITICAL Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade. | Mar 3, 2020 | 9.1 | 28 | NO | NO |
CVE-2025-69234CRITICAL Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment. | Dec 30, 2025 | 9.1 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA40 CVEs
30%
35%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (15.0%)
Network34 (85.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None29 (72.5%)
Unknown0 (0.0%)
Required11 (27.5%)
Privileges Required
Low5 (12.5%)
High1 (2.5%)
None34 (85.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Naver Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Naver Corporation as a CNA — matched by CVE ID, not by organization name.