$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-208 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-208

전체 목록

16건

CVE-2026-58272Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prio…0.3%보통5.3
CVE-2026-16037Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtu…0.3%높음7.5
CVE-2026-54875Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 pri…0.3%낮음3.7
CVE-2026-18036In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose r…0.3%높음8.2
CVE-2026-54872Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations wi…0.3%낮음3.7
CVE-2026-77696Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing s…0.2%낮음3.7
CVE-2026-87737An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel…0.2%보통5.9
CVE-2026-18040In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) a…0.1%보통5.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.