CWE-1188 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-1188 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2020-13927The previous default setting for Airflow's Experimental API was to allow all API requests without au…99.8%심각9.8● 실제 악용이 확인됨CVE-2023-27524Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that…97.4%심각9.8● 실제 악용이 확인됨CVE-2022-24706In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation …92.5%심각9.8● 실제 악용이 확인됨CVE-2025-48927The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump…11.1%보통5.3● 실제 악용이 확인됨CVE-2023-6448Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default a…2.1%심각9.8CVE-2026-52824Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets A…2.1%심각9.1CVE-2026-87827Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on …1.1%심각10.0CVE-2026-57127PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware…0.9%심각9.8
전체 목록
30건
CVE-2026-57147PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns t…0.8%심각9.8
CVE-2026-89139Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module register…0.6%높음8.7
CVE-2026-93338Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that …0.5%보통6.9
CVE-2026-61793Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes th…0.5%보통6.9
CVE-2026-103956Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 all…0.5%심각10.0
CVE-2026-102676Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.5%높음8.3
CVE-2026-57139PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src…0.4%심각9.8
CVE-2026-85494Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, M…0.4%높음8.7
CVE-2026-94634Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vu…0.4%높음8.2
CVE-2026-97055SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via …0.4%심각9.2
CVE-2026-57148PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls bac…0.4%심각9.8
CVE-2026-86464In the current development version of Eclipse aeriOS, for which no official release has yet been published, th…0.4%심각9.9
CVE-2026-53660Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration i…0.3%높음7.4
CVE-2026-100291In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management request…0.3%심각9.3
CVE-2026-49462NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residen…0.3%보통5.3
CVE-2026-54907Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.…0.3%보통5.3
CVE-2026-86246Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure o…0.3%심각9.1
CVE-2026-100260In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset0.3%보통5.3
CVE-2026-93354Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated a…0.3%높음8.5
CVE-2026-85086Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache…0.3%보통6.9
CVE-2026-73596Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of …0.2%낮음3.8
CVE-2026-71448: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentic…0.1%보통5.6
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.