CWE-1333 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-1333 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-89407NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" wit…0.6%높음7.5CVE-2026-68497jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGrego…0.6%높음7.5CVE-2026-92114A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of…0.5%보통6.9CVE-2026-77422JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine bu…0.5%높음7.5CVE-2026-76821OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables.…0.5%높음7.1CVE-2026-86000Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the se…0.4%보통5.3CVE-2026-93761An inefficient regular expression complexity issue in the in-memory query evaluation component of th…0.5%높음8.7CVE-2026-103043anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 hos…0.4%높음8.7
전체 목록
39건
CVE-2026-57577DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-fin…0.4%높음8.2
CVE-2026-77421JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nan…0.4%보통6.5
CVE-2026-63460Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an un…0.4%높음7.5
CVE-2026-96292Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift L…0.4%높음8.2
CVE-2026-104861probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg…0.4%높음7.5
CVE-2026-101906Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypass…0.4%높음8.2
CVE-2026-104454YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an…0.4%보통6.9
CVE-2026-101903Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regul…0.4%높음8.2
CVE-2026-77423JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in les…0.4%높음7.5
CVE-2026-85999Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in…0.4%보통5.3
CVE-2026-102990basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromi…0.4%높음8.2
CVE-2026-82617The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX…0.3%심각10.0
CVE-2026-92599joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular exp…0.3%높음8.7
CVE-2026-58270Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to vers…0.3%보통6.5
CVE-2026-86081n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone …0.3%높음7.1
CVE-2026-67989crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expressio…0.3%높음7.5
CVE-2026-67419RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a …0.3%높음7.1
CVE-2026-66074RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, mat…0.3%보통6.0
CVE-2026-87722Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectP…0.3%높음8.7
CVE-2026-85062Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, s…0.3%보통6.9
CVE-2026-75880An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results…0.3%보통6.5
CVE-2026-67413RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional …0.3%보통6.0
CVE-2026-87819GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_rege…0.3%높음8.7
CVE-2026-54461Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2,…0.3%보통6.5
CVE-2026-100267In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters0.3%보통5.9
CVE-2026-67240RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*…0.3%낮음2.3
CVE-2026-77387geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessi…0.2%보통4.0
CVE-2026-102270PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected…0.2%보통4.4
CVE-2026-102473A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbou…0.1%보통5.5
CVE-2026-77420JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPa…0.1%보통5.5
CVE-2026-105219Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map …높음8.7
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.