CVE-2025-62583Critical· 9.8▾ MidnightWhale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
whale < 4.33.325.17Upgrade past the affected range:
whale 4.33.325.17Connected by shared product, vendor, weakness, or advisory.
CVE-2025-69235High· 7.5Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
CVE-2026-1486High· 8.8A flaw was found in Keycloak
CVE-2025-59147High· 7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community
CVE-2025-31983Low· 3.7HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
CVE-2025-31970Medium· 5.3HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection v…
CVE-2026-102824Medium· 4.3Russh is a Rust SSH client and server library