CWE-200 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-200 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2024-24919Potentially allowing an attacker to read certain information on Check Point Security Gateways once c…100.0%높음8.6● 실제 악용이 확인됨CVE-2021-41277Metabase is an open source data analytics platform. In affected versions a security issue has been d…97.2%높음7.5● 실제 악용이 확인됨CVE-2016-6415The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through…87.7%높음7.5● 실제 악용이 확인됨CVE-2023-28432Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-…84.0%높음7.5● 실제 악용이 확인됨CVE-2023-49103An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The…78.4%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2020-3259A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software an…71.8%높음7.5● 실제 악용이 확인됨CVE-2025-31125Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using…65.2%높음7.5● 실제 악용이 확인됨CVE-2016-2388The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain …52.2%보통5.3
전체 목록
120건
CVE-2018-5430악용 확인The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community…49.0%높음8.8
CVE-2008-0655악용 확인Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack v…37.9%높음8.8
CVE-2026-20133악용 확인A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sens…31.8%높음7.5
CVE-2025-68686악용 확인An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortine…29.6%보통5.9
CVE-2015-5317악용 확인The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain s…23.0%높음7.5
CVE-2015-0310악용 확인Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11…15.1%높음7.8
CVE-2022-20821악용 확인A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attack…11.5%보통6.5
CVE-2026-20805악용 확인Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized att…7.2%보통5.5
CVE-2021-25369악용 확인An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive ker…1.1%보통5.5
CVE-2023-21237악용 확인In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service not…0.3%보통5.5
CVE-2026-69806Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate pr…1.8%높음7.0
CVE-2026-54649punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private…0.8%낮음2.1
CVE-2026-54617GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticat…0.7%심각9.8
CVE-2026-63646CordysCRM is an open source AI-powered customer relationship management system that supports private deploymen…0.7%보통6.9
CVE-2026-9289The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in…0.6%보통5.3
CVE-2026-76825RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a …0.6%높음8.4
CVE-2026-92708Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficien…0.6%높음7.5
CVE-2026-94413jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to…0.5%높음7.1
CVE-2026-76710A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the …0.5%높음7.5
CVE-2026-94148A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of th…0.5%보통5.5
CVE-2026-93971A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file back…0.5%보통6.9
CVE-2026-87820CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose ad…0.5%보통6.9
CVE-2026-92927A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown pr…0.5%보통5.5
CVE-2026-88874AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Liv…0.5%높음8.7
CVE-2026-69805External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a net…0.5%높음7.5
CVE-2026-85517A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown funct…0.5%보통5.5
CVE-2026-95693In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_…0.5%보통5.3
CVE-2026-95703In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with file…0.5%보통5.1
CVE-2026-86059Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members …0.5%심각9.6
CVE-2026-69862Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose inf…0.5%보통5.5
CVE-2026-61749InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author…0.5%보통6.5
CVE-2026-76697A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allo…0.5%보통6.5
CVE-2026-67100HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerab…0.5%심각9.8
CVE-2026-51995An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information v…0.5%높음7.5
CVE-2026-101055A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the fu…0.5%보통5.5
CVE-2026-92947vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used…0.4%심각10.0
CVE-2026-84990ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/sys…0.5%높음8.8
CVE-2026-92960vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allo…0.4%심각10.0
CVE-2026-76706A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthent…0.4%보통5.3
CVE-2026-93685A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint withou…0.4%보통5.4
CVE-2026-89278The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for Word…0.4%보통5.3
CVE-2026-84179Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration a…0.4%보통6.5
CVE-2026-73178Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator w…0.4%높음7.5
CVE-2026-92404The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoint…0.4%높음7.5
CVE-2026-91965WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin…0.4%높음8.7
CVE-2026-90881A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HN…0.4%보통5.5
CVE-2026-76712A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, info…0.4%높음7.3
CVE-2026-85055Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read pe…0.4%높음7.1
CVE-2026-55870GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators…0.4%낮음2.3
CVE-2026-77132It has been discovered that several AJAX routes used for the backend localization wizard failed to perform aut…0.4%보통5.3
CVE-2026-76717A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sen…0.4%보통5.3
CVE-2026-64684RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpCl…0.4%보통6.8
CVE-2026-76805Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz pay…0.4%보통5.3
CVE-2026-81270Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0…0.4%높음7.5
CVE-2026-67410RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed v…0.4%높음8.2
CVE-2026-89248AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization chec…0.4%보통6.9
CVE-2026-91985Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpo…0.4%높음8.7
CVE-2026-81531An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for …0.4%보통6.9
CVE-2026-69197Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and P…0.4%높음8.7
CVE-2026-78474The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisatio…0.4%보통5.3
CVE-2026-54529SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmi…0.4%보통5.3
CVE-2026-86064Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /l…0.4%높음8.6
CVE-2026-61746InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingLi…0.4%보통5.3
CVE-2026-88065`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules.…0.4%높음7.5
CVE-2026-85588phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files…0.4%보통5.3
CVE-2026-19300IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to inc…0.4%높음7.5
CVE-2026-55178GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. P…0.4%높음7.5
CVE-2026-47360Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_c…0.4%높음7.5
CVE-2026-87792The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the…0.4%높음8.7
CVE-2026-94050A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function router…0.4%보통5.3
CVE-2026-56729Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categorie…0.4%낮음2.1
CVE-2026-92916Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled…0.4%높음8.7
CVE-2026-86464In the current development version of Eclipse aeriOS, for which no official release has yet been published, th…0.4%심각9.9
CVE-2026-9004The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Ex…0.4%보통4.3
CVE-2026-16960The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data …0.4%높음7.5
CVE-2026-43687The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27…0.3%보통6.5
CVE-2026-104455YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to …0.4%보통6.9
CVE-2026-68852Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information local…0.3%보통5.5
CVE-2026-101143A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functiona…0.4%낮음2.1
CVE-2026-61782Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsd…0.4%높음7.5
CVE-2026-75158Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter re…0.4%보통4.3
CVE-2026-92917Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the…0.3%높음8.7
CVE-2026-85717The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously …0.3%보통6.8
CVE-2026-92770Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration acces…0.3%높음7.1
CVE-2026-86445The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrati…0.3%보통5.3
CVE-2026-86449The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user sup…0.3%보통5.3
CVE-2026-86447The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrati…0.3%보통5.3
CVE-2026-82124The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is passwo…0.3%보통5.3
CVE-2026-79323Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module…0.3%높음7.5
CVE-2026-100543OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original,…0.3%높음7.7
CVE-2026-86419Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed re…0.3%높음7.0
CVE-2026-63461Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collection…0.3%보통5.3
CVE-2026-75163An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X…0.3%보통6.5
CVE-2026-17585The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to …0.3%보통5.3
CVE-2026-54254Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrai…0.3%보통5.9
CVE-2026-86284A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199ed…0.3%보통5.5
CVE-2026-100418Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endp…0.3%보통6.9
CVE-2026-91766When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Pro…0.3%보통5.9
CVE-2026-88876AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerabilit…0.3%높음8.7
CVE-2026-62286Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go…0.3%보통4.3
CVE-2026-64761A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iP…0.3%높음7.5
CVE-2026-20360As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard eng…0.3%높음8.8
CVE-2026-86519A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the…0.3%보통5.5
CVE-2026-86179A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file …0.3%보통5.5
CVE-2026-49463NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residen…0.3%보통6.5
CVE-2026-18486IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain…0.3%높음8.8
CVE-2026-88893OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected re…0.3%높음8.7
CVE-2026-97179A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function…0.3%낮음2.1
CVE-2026-94611authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serial…0.3%높음8.1
CVE-2026-19858The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisatio…0.3%높음7.5
CVE-2026-86308A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c38…0.3%보통5.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.