CWE-178 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-178 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2020-12812An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and belo…45.4%심각9.8CVE-2026-77560Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded …0.6%높음8.1CVE-2026-54567Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, na…0.6%높음7.5CVE-2026-77281Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, thre…0.5%보통6.5CVE-2026-100669Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matche…0.4%높음8.7CVE-2026-92700Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in m…0.4%보통6.3CVE-2026-87876Two case-insensitive comparisons on request-derived usernames outside the main authorization path in…0.4%낮음3.0CVE-2026-102131Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did n…0.4%높음7.2
전체 목록
19건
CVE-2026-90982@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions bef…0.4%보통5.3
CVE-2026-89012Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API qu…0.3%높음7.1
CVE-2026-100580OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron…0.3%높음8.7
CVE-2026-100541OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase com…0.3%높음7.7
CVE-2026-86770Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attacke…0.3%높음8.6
CVE-2026-82067Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause th…0.3%심각9.2
CVE-2026-84428fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names…0.3%높음7.5
CVE-2026-57441MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior t…0.2%높음8.4
CVE-2026-86472fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4…0.2%보통4.8
CVE-2026-100693Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls…0.1%높음8.6
CVE-2021-48006PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.…0.1%보통4.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.