Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.1% | — | Naver Whale Browser Installer | 20/5/2020 | 17/6/2026 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. | |
| Modificada | Alta (7.8) | 0.90% | — | Navercorp Whale | 11/10/2018 | 17/6/2026 | The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. | |
| Modificada | Media (5.3) | 0.77% | — | Navercorp Whale | 2/8/2018 | 17/6/2026 | Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar when visiting a non-http page, which allows an attacker to display a malicious web page with a fake domain name. | |
| Modificada | Media (5.3) | 0.78% | — | Navercorp Whale | 3/7/2018 | 17/6/2026 | Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name. | |
| Modificada | Alta (8.1) | 0.92% | — | Navercorp Whale | 16/6/2018 | 17/6/2026 | The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications. | |
| Modificada | Alta (7.8) | 1.0% | — | Navercorp Whale | 8/1/2018 | 17/6/2026 | The Installer in Whale allows DLL hijacking. | |
| Modificada | Alta (7.5) | 1.1% | — | Bluewhalecrm | 8/9/2005 | 16/6/2026 | SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field. | |
| Modificada | Media (5) | 2.0% | — | Whale Communications E-gap | 31/12/2003 | 16/6/2026 | Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor. |