Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Navercorp

First CVE: Jan 8, 2018Active for: 9 yearsTotal CVEs: 22
38.6
VTI Score
Medium

Navercorp's vulnerability profile, while spanning a limited product portfolio, includes globally distributed applications such as Whale browser and MyBox cloud storage that reach beyond its domestic user base. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs across these products through weakness classes including improper security checks, incorrect privilege assignment, origin validation errors, and input-validation flaws that are characteristic of authentication and boundary-control boundaries in web and application platforms. The modest volume and narrow product scope should not be mistaken for limited risk—these applications' reach and access to user data elevate the significance of each disclosed vulnerability. Defenders should prioritize advisories from this vendor for any deployed instances of its browser or storage products; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Navercorp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 8, 2018
8 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-8148HIGH
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.
May 8, 20267.830NONO
CVE-2025-62583CRITICAL
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
Oct 16, 20259.830NONO
CVE-2022-24074CRITICAL
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whal
Mar 17, 20229.830NONO
CVE-2025-69234CRITICAL
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
Dec 30, 20259.127NONO
CVE-2025-53599CRITICAL
Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.
Jul 4, 20259.826NONO
CVE-2025-62585HIGH
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
Oct 16, 20257.525NONO
CVE-2025-58323HIGH
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege check
Aug 29, 20257.725NONO
CVE-2025-58322HIGH
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs due to improper privilege checks.
Aug 28, 20257.825NONO
CVE-2018-12449HIGH
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
Oct 11, 20187.825NONO
CVE-2025-69235HIGH
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
Dec 30, 20257.524NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
32%
50%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (22.7%)
Network17 (77.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None16 (72.7%)
Unknown0 (0.0%)
Required6 (27.3%)
Privileges Required
Low2 (9.1%)
High0 (0.0%)
None20 (90.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Navercorp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Navercorp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Navercorp's Products

View all 2 CNAs →

Top CWEs