$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-184 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-184

전체 목록

32건

CVE-2026-101884OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that…0.5%높음7.7
CVE-2026-61851Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data t…0.5%보통6.5
CVE-2026-70334Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a securit…0.4%높음7.8
CVE-2026-87985An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission chec…0.4%심각10.0
CVE-2026-79696A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.…0.4%심각10.0
CVE-2026-100253In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible…0.4%높음8.8
CVE-2026-57138PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builti…0.4%심각9.9
CVE-2026-75884A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only re…0.4%심각9.1
CVE-2026-63671MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0…0.4%높음8.1
CVE-2026-86199PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login auth…0.3%높음8.7
CVE-2026-82536Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that …0.3%높음7.7
CVE-2026-90808A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/…0.3%보통5.3
CVE-2026-84706A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environmen…0.3%높음7.6
CVE-2026-61788DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22…0.3%높음7.4
CVE-2026-11918IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass prote…0.3%보통5.4
CVE-2026-84714A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two r…0.3%높음7.1
CVE-2026-63206Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, w…0.3%보통5.3
CVE-2026-102828simple-git, an interface for running git commands in any node.js application, enables applications to execute …0.3%심각9.2
CVE-2026-102829simple-git, an interface for running git commands in any node.js application, enables applications to execute …0.3%심각9.2
CVE-2026-97149In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT request…0.2%보통5.3
CVE-2026-55096fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP …0.2%높음7.1
CVE-2026-85787An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server …0.2%높음7.1
CVE-2026-85788Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server …0.1%보통5.7
CVE-2026-33197AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallow…0.1%높음8.7
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.