$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-20 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-20

CWE-20 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

10.0PACWE-20● 랜섬웨어 캠페인에 사용됨CVE-2024-3400Palo Alto Networks · PAN-OSA command injection as a result of arbitrary file creation vulnerability in the GlobalProtect featur…100.0%심각10.010.0APCWE-20● 랜섬웨어 캠페인에 사용됨CVE-2021-44228Apache · Log4j2Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI …100.0%심각10.09.8VMCWE-918● 랜섬웨어 캠페인에 사용됨CVE-2021-21985VMware · vCenter ServerThe vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input valid…100.0%심각9.87.5CICWE-20● 실제 악용이 확인됨CVE-2020-3452Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an…100.0%높음7.59.8DRCWE-20● 랜섬웨어 캠페인에 사용됨CVE-2018-7600Drupal · Drupal CoreDrupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attac…100.0%심각9.89.8MICWE-20● 랜섬웨어 캠페인에 사용됨CVE-2019-0604Microsoft · SharePointA remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec…99.9%심각9.87.5CICWE-20● 실제 악용이 확인됨CVE-2018-0296Cisco · Adaptive Security Appliance (ASA)A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an u…99.9%높음7.59.8ZOCWE-20● 랜섬웨어 캠페인에 사용됨CVE-2022-47966Zoho · ManageEngineMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote…99.8%심각9.8

전체 목록

120건

CVE-2018-0171악용 확인A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an un…99.5%심각9.8
CVE-2017-0148랜섬웨어 악용The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.…99.4%높음8.1
CVE-2022-24086악용 확인Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input va…99.2%심각9.8
CVE-2023-22515랜섬웨어 악용Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have…99.2%심각9.8
CVE-2017-3881악용 확인A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE S…99.0%심각9.8
CVE-2017-9791악용 확인The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field v…98.9%심각9.8
CVE-2017-15944악용 확인Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allo…98.3%심각9.8
CVE-2016-3714악용 확인The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick…97.5%높음8.4
CVE-2023-23397악용 확인Microsoft Outlook Elevation of Privilege Vulnerability97.2%심각9.8
CVE-2020-1350악용 확인A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly …96.7%심각10.0
CVE-2009-0927악용 확인Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.…96.6%높음8.8
CVE-2019-1652악용 확인A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN…95.9%높음7.2
CVE-2024-21413악용 확인Microsoft Outlook Remote Code Execution Vulnerability94.7%심각9.8
CVE-2025-54236악용 확인Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affe…94.5%심각9.1
CVE-2012-0151악용 확인The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,…87.7%높음7.8
CVE-2023-2868악용 확인A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor…87.7%심각9.8
CVE-2020-3161악용 확인A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execu…83.9%심각9.8
CVE-2023-22952악용 확인In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates…80.1%높음8.8
CVE-2018-8414악용 확인A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka…72.9%높음8.8
CVE-2012-1535악용 확인Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.20…70.4%높음7.8
CVE-2019-1068악용 확인A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of…57.0%높음8.8
CVE-2019-11708악용 확인Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes …55.9%심각10.0
CVE-2022-29499랜섬웨어 악용The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because…55.2%심각9.8
CVE-2018-0125악용 확인A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VP…55.2%심각9.8
CVE-2026-12569랜섬웨어 악용A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPL…46.0%심각9.3
CVE-2026-34910악용 확인A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in…45.8%심각10.0
CVE-2026-32201악용 확인Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing o…43.4%보통6.5
CVE-2013-6282악용 확인The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platfor…39.7%높음8.8
CVE-2020-8195악용 확인Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21,…33.0%보통6.5
CVE-2025-20393악용 확인A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Ci…32.4%심각10.0
CVE-2018-19949랜섬웨어 악용If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNA…28.4%심각9.8
CVE-2023-36563악용 확인Microsoft WordPad Information Disclosure Vulnerability20.7%보통5.5
CVE-2023-36761악용 확인Microsoft Word Information Disclosure Vulnerability19.6%보통6.5
CVE-2018-0147악용 확인A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 …18.2%심각9.8
CVE-2026-34197악용 확인Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache A…15.5%높음8.8
CVE-2019-7193랜섬웨어 악용This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. T…14.4%심각9.8
CVE-2017-12240악용 확인The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability tha…13.8%심각9.8
CVE-2025-6558악용 확인Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a…9.6%높음8.8
CVE-2018-0156악용 확인A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an un…9.4%높음7.5
CVE-2015-2291랜섬웨어 악용(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for W…9.0%높음7.8
CVE-2024-38189악용 확인Microsoft Project Remote Code Execution Vulnerability8.2%높음8.8
CVE-2018-0172악용 확인A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Softw…7.8%높음8.6
CVE-2018-0174악용 확인A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Softw…7.6%높음8.6
CVE-2018-0173악용 확인A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option…7.6%높음8.6
CVE-2020-1040악용 확인A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly val…7.4%심각9.0
CVE-2018-0158악용 확인A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE S…7.2%높음8.6
CVE-2017-12234악용 확인Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12…7.1%높음7.5
CVE-2017-12235악용 확인A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco …7.1%높음7.5
CVE-2017-12233악용 확인Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12…7.1%높음7.5
CVE-2018-0159악용 확인A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS So…6.9%높음7.5
CVE-2022-3075악용 확인Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who ha…5.8%심각9.6
CVE-2017-12319악용 확인A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco…5.2%보통5.9
CVE-2021-38000악용 확인Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowe…4.9%보통6.1
CVE-2022-2856악용 확인Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allo…4.5%보통6.5
CVE-2024-30040악용 확인Windows MSHTML Platform Security Feature Bypass Vulnerability3.9%높음8.8
CVE-2023-41061악용 확인A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPa…3.8%높음7.8
CVE-2021-35247악용 확인Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. S…3.5%보통5.3
CVE-2025-8876악용 확인Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-c…3.4%심각9.4
CVE-2009-2055악용 확인Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BG…3.3%보통5.9
CVE-2020-0041악용 확인In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. T…3.1%높음7.8
CVE-2026-6973악용 확인An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely…2.5%높음7.2
CVE-2025-32706악용 확인Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate pr…2.3%높음7.8
CVE-2020-11261악용 확인Memory corruption due to improper check to return error when user application requests memory allocation of a …1.6%높음7.8
CVE-2021-36742악용 확인A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Wo…1.5%높음7.8
CVE-2026-88771악용 확인Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affec…1.1%심각9.5
CVE-2026-93952악용 확인VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to acce…1.1%심각9.5
CVE-2021-25489악용 확인Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 …0.5%보통5.5
CVE-2026-12268ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF…4.7%높음8.8
CVE-2026-12267ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resoluti…3.6%높음7.2
CVE-2026-75638CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Secur…1.3%보통6.5
CVE-2026-81995Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result…1.2%심각9.1
CVE-2026-54501Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or us…1.2%심각9.4
CVE-2026-85750Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling …1.2%높음7.2
CVE-2026-18911ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing…1.1%높음7.5
CVE-2026-76194CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Secur…1.0%보통4.3
CVE-2026-75634CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Secur…1.0%보통4.3
CVE-2026-85979Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_k…1.0%높음8.6
CVE-2026-72977Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over…1.0%보통6.5
CVE-2026-69845Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a netwo…0.9%심각9.8
CVE-2026-78518Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.0.9%높음8.8
CVE-2026-69614Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a …0.9%높음8.8
CVE-2026-73547Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.…0.8%높음7.5
CVE-2026-91932Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authentic…0.8%심각9.0
CVE-2026-68839Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute…0.8%심각9.8
CVE-2026-86679ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validati…0.8%높음7.1
CVE-2026-93568A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTT…0.8%높음7.5
CVE-2026-93567A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component inc…0.7%높음7.5
CVE-2026-73513Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.…0.7%높음7.5
CVE-2026-86683ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change t…0.7%높음8.1
CVE-2022-51015PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BR…0.7%높음7.1
CVE-2026-73552Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.…0.7%높음7.5
CVE-2026-81180SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysRept…0.7%높음8.8
CVE-2026-19480CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Secur…0.7%높음7.5
CVE-2026-88064Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, t…0.6%높음8.8
CVE-2026-81876HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior…0.6%높음7.5
CVE-2026-81875HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior…0.6%높음7.5
CVE-2026-75686Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code ex…0.6%심각9.3
CVE-2026-93295MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as th…0.6%보통5.1
CVE-2026-95679MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying …0.6%보통6.9
CVE-2026-61794Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant upd…0.6%보통6.8
CVE-2026-94379The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several s…0.6%보통6.9
CVE-2026-67234RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term…0.6%낮음2.3
CVE-2026-85532Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could …0.5%높음7.5
CVE-2026-54632SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived…0.5%높음7.5
CVE-2026-51997An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the…0.5%높음8.8
CVE-2026-82008Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in ar…0.5%심각9.9
CVE-2026-43692A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27…0.5%높음8.8
CVE-2022-51013PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data re…0.5%높음7.1
CVE-2022-51012PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of invento…0.5%높음7.1
CVE-2022-51010PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT …0.5%높음7.1
CVE-2026-81392Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.0.5%보통5.5
CVE-2026-95703In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with file…0.5%보통5.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.