CWE-209 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-209 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-29059.NET Framework Information Disclosure Vulnerability98.6%높음7.5● 실제 악용이 확인됨CVE-2025-47813loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the appli…63.1%보통4.3● 실제 악용이 확인됨CVE-2013-7331The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to…50.2%보통6.5CVE-2026-67383Generation of error message containing sensitive information in SQL Server allows an authorized atta…1.0%보통6.5CVE-2026-69552Generation of error message containing sensitive information in Windows Print Spooler Components all…0.9%보통5.7CVE-2026-66306Generation of error message containing sensitive information in Skype for Business allows an unautho…0.5%보통6.5CVE-2026-45723Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, ma…0.5%낮음2.7CVE-2026-68886Use after free in Windows Network Connection Broker allows an authorized attacker to disclose inform…0.5%보통5.5
전체 목록
29건
CVE-2026-69684Generation of error message containing sensitive information in Windows Error Reporting allows an authorized a…0.5%보통5.5
CVE-2026-92936vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack f…0.4%보통6.9
CVE-2026-85709LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server retu…0.4%보통5.3
CVE-2026-84499A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type pas…0.4%높음7.7
CVE-2026-69294Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized…0.3%보통5.5
CVE-2026-54561MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0,…0.3%보통6.2
CVE-2026-71463Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_…0.3%낮음2.7
CVE-2026-4638PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer p…0.3%높음7.1
CVE-2026-55375canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request…0.3%보통5.3
CVE-2026-100677stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes sourc…0.3%보통6.9
CVE-2026-67106HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API e…0.2%보통5.3
CVE-2026-67171HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API en…0.2%보통5.3
CVE-2026-3626IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed …0.2%보통5.3
CVE-2025-1350IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtai…0.2%보통5.3
CVE-2026-1030IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates …0.2%보통4.3
CVE-2026-71461HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user tr…0.2%보통4.3
CVE-2026-67172HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns s…0.2%낮음3.7
CVE-2026-102904JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb…0.2%보통5.4
CVE-2026-4921IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a de…0.2%낮음2.7
CVE-2026-66248iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacke…0.2%낮음3.1
CVE-2026-55102hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API met…0.1%보통5.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.