CWE-208 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-208 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-77987A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub E…0.9%심각9.3CVE-2023-24035An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses…0.8%낮음3.5CVE-2026-88010Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassw…0.7%보통6.3CVE-2026-70658Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBil…0.5%높음7.4CVE-2026-63132OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handle…0.5%심각9.2CVE-2026-77582Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely …0.5%보통6.9CVE-2026-95270A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the funct…0.4%낮음2.9CVE-2026-85725LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in…0.4%보통5.9
전체 목록
16건
CVE-2026-58272Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prio…0.3%보통5.3
CVE-2026-16037Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtu…0.3%높음7.5
CVE-2026-54875Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 pri…0.3%낮음3.7
CVE-2026-18036In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose r…0.3%높음8.2
CVE-2026-54872Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations wi…0.3%낮음3.7
CVE-2026-77696Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing s…0.2%낮음3.7
CVE-2026-87737An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel…0.2%보통5.9
CVE-2026-18040In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) a…0.1%보통5.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.