$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
악용 확인1,695최근 7일 신규10한국어 권고 연결46CVE악용 확인 전체 →
CVE Ledger

CVE 원장

수집된 취약점입니다. CVSS 점수 순으로 정렬하지 않습니다 — 점수는 "얼마나 나쁠 수 있는가" 이고, 우리가 먼저 묻는 것은 "실제로 쓰이고 있는가" 입니다.

원장 2,889이 중 악용 확인 1,695정렬: 악용 확인 → EPSS 백분위 → 공개일

우선순위 목록

CVE-2024-3400랜섬웨어 악용A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo …100.0%심각10.0
CVE-2021-44228랜섬웨어 악용Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features u…100.0%심각10.0
CVE-2020-5902랜섬웨어 악용In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, th…100.0%심각9.8
CVE-2024-21893랜섬웨어 악용A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Iva…100.0%높음8.2
CVE-2024-21887랜섬웨어 악용A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Sec…100.0%심각9.1
CVE-2023-44487악용 확인The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can …100.0%높음7.5
CVE-2019-0708랜섬웨어 악용A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services wh…100.0%심각9.8
CVE-2023-4966랜섬웨어 악용Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virt…100.0%높음7.5
CVE-2021-22005랜섬웨어 악용The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor…100.0%심각9.8
CVE-2019-19781랜섬웨어 악용An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, an…100.0%심각9.8
CVE-2015-1635악용 확인HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 20…100.0%심각9.8
CVE-2021-40438랜섬웨어 악용A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remot…100.0%심각9.0
CVE-2021-34473랜섬웨어 악용Microsoft Exchange Server Remote Code Execution Vulnerability100.0%심각9.1
CVE-2014-0160악용 확인The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Exten…100.0%높음7.5
CVE-2023-22518랜섬웨어 악용All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Imprope…100.0%심각9.8
CVE-2023-35082랜섬웨어 악용An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access res…100.0%심각9.8
CVE-2023-0669랜섬웨어 악용Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerabilit…100.0%높음7.2
CVE-2019-11510랜섬웨어 악용In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an…100.0%심각10.0
CVE-2024-23897랜섬웨어 악용Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that r…100.0%심각9.8
CVE-2023-35078랜섬웨어 악용An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functiona…100.0%심각9.8
CVE-2023-27350랜섬웨어 악용This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 2…100.0%심각9.8
CVE-2022-29464랜섬웨어 악용Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must u…100.0%심각9.8
CVE-2018-13379랜섬웨어 악용An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to…100.0%심각9.8
CVE-2017-9841악용 확인Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbit…100.0%심각9.8
CVE-2017-5638랜섬웨어 악용The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect ex…100.0%심각9.8
CVE-2022-26134랜섬웨어 악용In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would a…100.0%심각9.8
CVE-2021-26084랜섬웨어 악용In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would a…100.0%심각9.8
CVE-2021-35464랜섬웨어 악용ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on m…100.0%심각9.8
CVE-2014-6271악용 확인GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variab…100.0%심각9.8
CVE-2023-32315악용 확인Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a…100.0%높음7.5
CVE-2023-1389악용 확인TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulne…100.0%높음8.8
CVE-2021-26086악용 확인Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via…100.0%보통5.3
CVE-2021-21985랜섬웨어 악용The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in t…100.0%심각9.8
CVE-2023-1671악용 확인A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than vers…100.0%심각9.8
CVE-2021-1498악용 확인Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenti…100.0%심각9.8
CVE-2025-53770랜섬웨어 악용Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker t…100.0%심각9.8
CVE-2017-7921악용 확인An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.…100.0%심각9.8
CVE-2013-2251악용 확인Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a paramet…100.0%심각9.8
CVE-2012-1823악용 확인sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi)…100.0%심각9.8
CVE-2024-3273악용 확인** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320…100.0%심각9.8
CVE-2022-22954랜섬웨어 악용VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-s…100.0%심각9.8
CVE-2020-14882악용 확인Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supporte…100.0%심각9.8
CVE-2019-16920악용 확인Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1…100.0%심각9.8
CVE-2025-49704랜섬웨어 악용Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized …100.0%높음8.8
CVE-2021-26855랜섬웨어 악용Microsoft Exchange Server Remote Code Execution Vulnerability100.0%심각9.1
CVE-2024-34102악용 확인Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restrictio…100.0%심각9.8
CVE-2022-44877악용 확인login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers…100.0%심각9.8
CVE-2020-8515악용 확인DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta dev…100.0%심각9.8
CVE-2017-10271랜섬웨어 악용Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security)…100.0%높음7.5
CVE-2024-13159악용 확인Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S…100.0%높음7.5
CVE-2021-41773랜섬웨어 악용A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a …100.0%심각9.8
CVE-2020-3452악용 확인A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fi…100.0%높음7.5
CVE-2018-11776악용 확인Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysS…100.0%높음8.1
CVE-2024-27199랜섬웨어 악용In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible100.0%높음7.3
CVE-2023-29300랜섬웨어 악용Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are af…100.0%심각9.8
CVE-2018-7600랜섬웨어 악용Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to ex…100.0%심각9.8
CVE-2025-3248랜섬웨어 악용Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A re…100.0%심각9.8
CVE-2024-7593악용 확인Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 all…100.0%심각9.8
CVE-2021-34523랜섬웨어 악용Microsoft Exchange Server Elevation of Privilege Vulnerability100.0%심각9.0
CVE-2017-12617악용 확인When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.8…100.0%높음8.1
CVE-2024-4577랜섬웨어 악용In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on…100.0%심각9.8
CVE-2023-46805랜섬웨어 악용An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure a…100.0%높음8.2
CVE-2020-9054악용 확인Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authenticati…100.0%심각9.8
CVE-2019-9670악용 확인mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity inj…100.0%심각9.8
CVE-2023-22527랜섬웨어 악용A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenti…100.0%심각9.8
CVE-2023-29357랜섬웨어 악용Microsoft SharePoint Server Elevation of Privilege Vulnerability100.0%심각9.8
CVE-2022-40684랜섬웨어 악용An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 throug…100.0%심각9.8
CVE-2025-22457랜섬웨어 악용A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before ve…100.0%심각9.8
CVE-2024-45195악용 확인Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.1…100.0%높음7.5
CVE-2021-20090악용 확인A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR…100.0%심각9.8
CVE-2021-22204악용 확인Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary…100.0%높음7.8
CVE-2025-59287악용 확인Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute …100.0%심각9.8
CVE-2025-0282랜섬웨어 악용A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before ve…100.0%심각9.0
CVE-2024-1709랜섬웨어 악용ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or…100.0%심각10.0
CVE-2023-42793랜섬웨어 악용In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible100.0%심각9.8
CVE-2024-24919랜섬웨어 악용Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected t…100.0%높음8.6
CVE-2023-4863악용 확인Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote at…100.0%높음8.8
CVE-2021-45046랜섬웨어 악용It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-defau…100.0%심각9.0
CVE-2025-31161랜섬웨어 악용CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin acc…100.0%심각9.8
CVE-2024-4879악용 확인ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC …100.0%심각9.3
CVE-2012-0158랜섬웨어 악용The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Commo…100.0%높음8.8
CVE-2022-41082랜섬웨어 악용Microsoft Exchange Server Remote Code Execution Vulnerability100.0%높음8.0
CVE-2021-3156악용 확인Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows…100.0%높음7.8
CVE-2014-8361악용 확인The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInt…100.0%심각9.8
CVE-2022-47986랜섬웨어 악용IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on t…100.0%심각9.8
CVE-2020-25506악용 확인D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which…100.0%심각9.8
CVE-2025-5777랜섬웨어 악용Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN vi…100.0%심각9.3
CVE-2021-42013랜섬웨어 악용It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could …100.0%심각9.8
CVE-2020-0688랜섬웨어 악용A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properl…100.0%높음8.8
CVE-2019-2725랜섬웨어 악용Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)…100.0%심각9.8
CVE-2024-38475악용 확인Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map …100.0%심각9.1
CVE-2022-41040랜섬웨어 악용Microsoft Exchange Server Elevation of Privilege Vulnerability100.0%높음8.8
CVE-2022-1388랜섬웨어 악용On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14…100.0%심각9.8
CVE-2019-10149악용 확인A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in delive…100.0%심각9.8
CVE-2024-29824악용 확인An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthent…100.0%높음8.8
CVE-2023-38035랜섬웨어 악용A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may…100.0%심각9.8
CVE-2018-15961악용 확인Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier h…100.0%심각9.8
CVE-2018-10562랜섬웨어 악용An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in…100.0%심각9.8
CVE-2022-30525악용 확인A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 throug…99.9%심각9.8
CVE-2021-3129랜섬웨어 악용Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execu…99.9%심각9.8
CVE-2017-11882랜섬웨어 악용Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack…99.9%높음7.8
CVE-2024-27198랜섬웨어 악용In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible99.9%심각9.8
CVE-2020-10189악용 확인Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of u…99.9%심각9.8
CVE-2015-3113악용 확인Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on …99.9%심각9.8
CVE-2014-7169악용 확인GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the…99.9%심각9.8
CVE-2023-34362랜섬웨어 악용In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5),…99.9%심각9.8
CVE-2022-22963악용 확인In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionalit…99.9%심각9.8
CVE-2021-26085랜섬웨어 악용Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre…99.9%보통5.3
CVE-2021-39226악용 확인Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated …99.9%높음7.3
CVE-2021-38647랜섬웨어 악용Open Management Infrastructure (OMI) Remote Code Execution Vulnerability99.9%심각9.8
CVE-2017-0199랜섬웨어 악용Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Micros…99.9%높음7.8
CVE-2025-24813악용 확인Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure an…99.9%심각9.8
CVE-2022-35405악용 확인Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated r…99.9%심각9.8
CVE-2021-1497악용 확인Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenti…99.9%심각9.8
CVE-2026-10520악용 확인An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows…99.9%심각10.0
CVE-2025-4427악용 확인An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows atta…99.9%높음7.5
CVE-2019-3396랜섬웨어 악용The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x),…99.9%심각9.8
CVE-2019-0604랜섬웨어 악용A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the sour…99.9%심각9.8
CVE-2024-45519악용 확인The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 befo…99.9%심각9.8
CVE-2021-20038랜섬웨어 악용A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variabl…99.9%심각9.8
CVE-2018-0296악용 확인A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthentic…99.9%높음7.5
CVE-2026-31431악용 확인In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating o…99.9%높음7.8
CVE-2020-7961악용 확인Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute a…99.9%심각9.8
CVE-2019-7481랜섬웨어 악용Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resource…99.9%높음7.5
CVE-2015-1427악용 확인The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to by…99.9%심각9.8
CVE-2023-21839악용 확인Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported v…99.9%높음7.5
CVE-2021-22986랜섬웨어 악용On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.…99.9%심각9.8
CVE-2014-0497악용 확인Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Wind…99.9%심각9.8
CVE-2021-27065랜섬웨어 악용Microsoft Exchange Server Remote Code Execution Vulnerability99.9%높음7.8
CVE-2021-44515악용 확인Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on …99.9%심각9.8
CVE-2021-36260악용 확인A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input v…99.9%심각9.8
CVE-2021-33044악용 확인The identity authentication bypass vulnerability found in some Dahua products during the login process. Attack…99.9%심각9.8
CVE-2019-1653악용 확인A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN…99.9%높음7.5
CVE-2025-24893악용 확인XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any g…99.9%심각9.8
CVE-2021-35394악용 확인Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually c…99.9%심각9.8
CVE-2021-21972랜섬웨어 악용The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malici…99.9%심각9.8
CVE-2025-32432악용 확인Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting…99.8%심각10.0
CVE-2023-23752악용 확인An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to…99.8%보통5.3
CVE-2022-46169악용 확인Cacti is an open source platform which provides a robust and extensible operational monitoring and fault manag…99.8%심각9.8
CVE-2024-36401악용 확인GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22…99.8%심각9.8
CVE-2021-37415악용 확인Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-…99.8%심각9.8
CVE-2017-7269악용 확인Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (I…99.8%심각9.8
CVE-2020-0796랜섬웨어 악용A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) …99.8%심각10.0
CVE-2016-6277악용 확인NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before…99.8%높음8.8
CVE-2025-55182랜섬웨어 악용A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19…99.8%심각10.0
CVE-2025-10035랜섬웨어 악용A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a valid…99.8%심각9.8
CVE-2023-29298악용 확인Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are af…99.8%높음7.5
CVE-2022-1040악용 확인An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute cod…99.8%심각9.8
CVE-2021-34527랜섬웨어 악용A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privil…99.8%높음8.8
CVE-2021-31207랜섬웨어 악용Microsoft Exchange Server Security Feature Bypass Vulnerability99.8%보통6.6
CVE-2020-13927악용 확인The previous default setting for Airflow's Experimental API was to allow all API requests without authenticati…99.8%심각9.8
CVE-2019-11043랜섬웨어 악용In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM…99.8%심각9.8
CVE-2025-25257악용 확인An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89]…99.8%심각9.8
CVE-2021-31166악용 확인HTTP Protocol Stack Remote Code Execution Vulnerability99.8%심각9.8
CVE-2019-15107랜섬웨어 악용An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injecti…99.8%심각9.8
CVE-2023-38205악용 확인Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by…99.7%높음7.5
CVE-2023-3519랜섬웨어 악용Unauthenticated remote code execution99.7%심각9.8
CVE-2022-47966랜섬웨어 악용Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code exec…99.8%심각9.8
CVE-2020-15505악용 확인A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, …99.7%심각9.8
CVE-2023-46604랜섬웨어 악용The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a r…99.7%심각9.8
CVE-2021-22205랜섬웨어 악용An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properl…99.7%심각10.0
CVE-2019-18935랜섬웨어 악용Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the …99.7%심각9.8
CVE-2019-16759악용 확인vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/re…99.7%심각9.8
CVE-2025-61882랜섬웨어 악용Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher …99.7%심각9.8
CVE-2010-2861랜섬웨어 악용Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlie…99.7%심각9.8
CVE-2024-0012랜섬웨어 악용An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with networ…99.7%심각9.3
CVE-2016-10033악용 확인The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass …99.7%심각9.8
CVE-2022-35914악용 확인/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code inje…99.7%심각9.8
CVE-2017-1000353악용 확인Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remot…99.7%심각9.8
CVE-2017-0147랜섬웨어 악용The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.…99.7%높음7.5
CVE-2025-48703악용 확인CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution…99.7%심각9.0
CVE-2022-22965악용 확인A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) …99.6%심각9.8
CVE-2024-9465악용 확인An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal E…99.6%심각9.2
CVE-2024-5217악용 확인ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver…99.6%심각9.2
CVE-2014-6278악용 확인GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment vari…99.6%높음8.8
CVE-2024-28995악용 확인SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sen…99.6%높음7.5
CVE-2017-12615랜섬웨어 악용When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly in…99.6%높음8.1
CVE-2026-8037악용 확인OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenti…99.6%심각9.8
CVE-2023-20198악용 확인Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in…99.6%심각10.0
CVE-2020-16846악용 확인An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the…99.6%심각9.8
CVE-2024-4040악용 확인A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all pla…99.5%심각10.0
CVE-2021-33045악용 확인The identity authentication bypass vulnerability found in some Dahua products during the login process. Attack…99.6%심각9.8
CVE-2025-31324랜섬웨어 악용SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthe…99.5%심각9.8
CVE-2018-20062악용 확인An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arb…99.5%심각9.8
CVE-2022-42475랜섬웨어 악용A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0…99.5%심각9.8
CVE-2018-0171악용 확인A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an un…99.5%심각9.8
CVE-2024-23692랜섬웨어 악용Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerabilit…99.5%심각9.8
CVE-2018-2628악용 확인Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Comp…99.4%심각9.8
CVE-2024-32113악용 확인Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.T…99.4%심각9.8
CVE-2023-34048악용 확인vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A m…99.4%심각9.8
CVE-2017-7494랜섬웨어 악용Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerabi…99.4%심각9.8
CVE-2024-38856악용 확인Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. User…99.4%심각9.8
CVE-2017-9805악용 확인The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHand…99.4%높음8.1
CVE-2011-0611악용 확인Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on …99.4%높음8.8
CVE-2021-32030악용 확인The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_…99.4%심각9.8
CVE-2020-1472랜섬웨어 악용An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure chann…99.4%보통5.5
CVE-2017-0148랜섬웨어 악용The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.…99.4%높음8.1
CVE-2022-0543악용 확인It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debia…99.4%심각10.0
CVE-2015-5119악용 확인Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash …99.3%심각9.8
CVE-2014-6287악용 확인The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x bef…99.3%심각9.8
설명은 NVD 영문 원문입니다. 번역하지 않습니다 — 보안 문서의 오역은 조치를 바꿉니다.
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.