CWE-1321 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-1321 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2026-34621Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Control…2.2%높음8.6CVE-2026-61534Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store a…0.8%심각9.1CVE-2026-85625sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, a…0.5%심각9.2CVE-2026-101900Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveC…0.5%보통6.9CVE-2026-93753deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function t…0.5%높음8.7CVE-2026-104848Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs…0.5%심각9.5CVE-2026-91860A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Com…0.5%보통6.3CVE-2026-94646Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modifi…0.5%높음8.7
전체 목록
35건
CVE-2026-86536Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apa…0.5%보통6.3
CVE-2026-102992piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadP…0.4%심각9.2
CVE-2026-55451gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() …0.4%높음8.3
CVE-2026-101904Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest…0.4%보통6.9
CVE-2026-101908Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter c…0.4%보통6.9
CVE-2026-101902Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios d…0.4%보통6.9
CVE-2026-63376toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be…0.4%높음8.2
CVE-2026-104849Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from …0.4%심각9.5
CVE-2026-55091flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, Fla…0.4%높음7.5
CVE-2026-92779Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the de…0.4%높음7.2
CVE-2026-102600Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/c…0.4%높음7.5
CVE-2026-101909Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.…0.4%높음8.3
CVE-2026-97151mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in…0.4%높음8.4
CVE-2026-69200node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the int…0.3%낮음3.7
CVE-2026-86078n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summa…0.3%보통6.0
CVE-2026-85063node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2…0.3%보통6.9
CVE-2026-86535Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype…0.3%높음8.7
CVE-2026-81994Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype…0.3%높음8.2
CVE-2026-101905Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adap…0.3%높음7.6
CVE-2026-89011isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that a…0.3%높음7.1
CVE-2026-61834scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited propert…0.3%보통4.3
CVE-2026-92781Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the un…0.3%보통5.3
CVE-2026-90771joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilatio…0.3%보통6.3
CVE-2026-97724A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker…0.3%보통5.3
CVE-2026-103036oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1…0.2%보통6.5
CVE-2026-103918oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1…0.2%보통6.5
CVE-2026-104183stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footpr…0.2%보통5.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.