$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-116 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-116

전체 목록

34건

CVE-2026-54182backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…0.4%높음8.1
CVE-2026-95274Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had…0.4%높음8.3
CVE-2026-82756Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows a…0.4%보통6.3
CVE-2026-95659MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject…0.4%보통4.8
CVE-2026-88921MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsi…0.4%보통5.1
CVE-2026-19641On affected platforms running Arista EOS with password authentication configured, a specially crafted password…0.3%보통6.9
CVE-2026-73195Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a sprea…0.3%높음7.3
CVE-2026-104907MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remo…0.4%보통4.8
CVE-2026-58504draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or impor…0.4%보통6.1
CVE-2026-13635An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) bef…0.3%보통5.3
CVE-2026-69821Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized …0.3%높음7.8
CVE-2026-54506Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior …0.3%높음7.6
CVE-2026-63208Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph req…0.3%보통5.1
CVE-2026-63329Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request i…0.3%보통4.9
CVE-2026-54694SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combin…0.3%심각9.6
CVE-2026-55214GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician…0.3%높음8.5
CVE-2026-82409Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go seria…0.3%높음8.4
CVE-2026-87550Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attack…0.2%보통4.3
CVE-2026-13407The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submi…0.2%보통5.4
CVE-2026-79952Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통5.3
CVE-2026-79964Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통5.3
CVE-2026-52772YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('…0.2%보통5.5
CVE-2026-61784xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, truste…0.2%보통6.1
CVE-2026-57583OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from Op…0.1%낮음3.3
CVE-2026-47562NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could injec…0.1%보통4.4
CVE-2026-77404RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, Ke…0.1%높음8.7
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.