CWE-1390 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-1390 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2026-55040Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a secur…17.5%심각9.1CVE-2026-73025Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature ov…0.9%심각9.8CVE-2026-62895Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker t…0.7%높음8.8CVE-2026-77483Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network…0.5%높음8.8CVE-2026-96940Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileg…0.5%높음8.8CVE-2026-92289Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Rel…0.4%미평가CVE-2026-92288Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow u…0.4%심각9.1CVE-2026-93355LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT fro…0.3%높음7.6
전체 목록
10건
CVE-2026-94455An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any sess…0.3%높음7.1
CVE-2026-80219A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-sco…0.2%높음8.7
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.