CWE-22 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-22 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2020-5902In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2019-11510In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9…100.0%심각10.0● 랜섬웨어 캠페인에 사용됨CVE-2019-19781An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2021-22005The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malic…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2024-23897Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command par…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2018-13379An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiO…100.0%심각9.8● 실제 악용이 확인됨CVE-2023-32315Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative …100.0%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2022-29464Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attac…100.0%심각9.8
전체 목록
120건
CVE-2021-26086악용 확인Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via…100.0%보통5.3
CVE-2020-3452악용 확인A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fi…100.0%높음7.5
CVE-2024-27199랜섬웨어 악용In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible100.0%높음7.3
CVE-2021-41773랜섬웨어 악용A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a …100.0%심각9.8
CVE-2021-20090악용 확인A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR…100.0%심각9.8
CVE-2021-42013랜섬웨어 악용It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could …100.0%심각9.8
CVE-2024-32113악용 확인Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.T…99.9%심각9.8
CVE-2019-3396랜섬웨어 악용The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x),…99.9%심각9.8
CVE-2018-0296악용 확인A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthentic…99.9%높음7.5
CVE-2021-21972랜섬웨어 악용The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malici…99.9%심각9.8
CVE-2010-2861랜섬웨어 악용Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlie…99.7%심각9.8
CVE-2024-28995악용 확인SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sen…99.6%높음7.5
CVE-2024-4885악용 확인In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in P…99.3%심각9.8
CVE-2022-30333랜섬웨어 악용RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka…99.2%높음7.5
CVE-2019-16278악용 확인Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve…99.0%심각9.8
CVE-2023-47246랜섬웨어 악용In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker …98.9%심각9.8
CVE-2022-27925랜섬웨어 악용Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and ext…98.7%높음7.2
CVE-2024-8963악용 확인Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restr…98.6%심각9.1
CVE-2019-5418악용 확인There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3…98.5%높음7.5
CVE-2024-41713랜섬웨어 악용A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.…98.1%심각9.1
CVE-2020-11738악용 확인The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Direct…97.8%높음7.5
CVE-2025-34028악용 확인The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that repre…97.6%심각9.3
CVE-2021-40444랜섬웨어 악용Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft W…97.5%높음8.8
CVE-2020-14864악용 확인Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (comp…97.2%높음7.5
CVE-2021-41277악용 확인Metabase is an open source data analytics platform. In affected versions a security issue has been discovered …97.2%높음7.5
CVE-2019-3398악용 확인Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A…97.0%높음8.8
CVE-2024-57727랜섬웨어 악용SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities …96.6%높음7.5
CVE-2021-20124악용 확인A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionalit…96.3%높음7.5
CVE-2018-14847악용 확인MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote auth…96.1%심각9.1
CVE-2018-20250랜섬웨어 악용In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filena…96.0%높음7.8
CVE-2025-61884랜섬웨어 악용Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported…95.9%높음7.5
CVE-2020-5410악용 확인Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versi…95.6%높음7.5
CVE-2016-0752악용 확인Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.…95.5%높음7.5
CVE-2024-1708랜섬웨어 악용ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an at…95.4%높음8.4
CVE-2022-41352랜섬웨어 악용An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files t…95.5%심각9.8
CVE-2017-12637악용 확인Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Appl…95.1%높음7.5
CVE-2026-85706악용 확인GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.…93.0%심각10.0
CVE-2023-38950악용 확인A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to …92.5%높음7.5
CVE-2024-7399악용 확인Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server versio…91.9%심각9.8
CVE-2022-37042랜섬웨어 악용Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and e…91.9%심각9.8
CVE-2025-6218악용 확인RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attack…90.5%높음7.8
CVE-2021-20123악용 확인A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionalit…90.2%높음7.5
CVE-2019-7195랜섬웨어 악용This external control of file name or path vulnerability allows remote attackers to access or modify system fi…89.7%심각9.8
CVE-2021-43798악용 확인Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.…88.5%높음7.5
CVE-2020-11652악용 확인An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process Clea…86.2%보통6.5
CVE-2025-8110악용 확인Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.85.2%높음8.7
CVE-2023-41266랜섬웨어 악용A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and ea…84.8%보통6.5
CVE-2015-3035악용 확인Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmwa…83.9%높음7.5
CVE-2019-7194랜섬웨어 악용This external control of file name or path vulnerability allows remote attackers to access or modify system fi…83.1%심각9.8
CVE-2024-0769악용 확인** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as crit…82.7%심각9.8
CVE-2018-18809악용 확인The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Li…79.1%보통6.5
CVE-2015-0016악용 확인Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, …75.8%높음7.8
CVE-2014-0780악용 확인Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote a…74.7%심각9.8
CVE-2020-36193악용 확인Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate check…70.6%높음7.5
CVE-2020-4430악용 확인IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse d…68.5%보통4.3
CVE-2024-57728랜섬웨어 악용SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on …64.7%높음7.2
CVE-2015-4068악용 확인Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensit…63.6%심각9.1
CVE-2023-35081악용 확인A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11…63.6%높음7.2
CVE-2014-0130악용 확인Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render impleme…53.7%높음7.5
CVE-2021-20023랜섬웨어 악용SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker t…51.4%보통4.9
CVE-2018-5430악용 확인The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community…49.0%높음8.8
CVE-2016-3976악용 확인Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arb…47.3%높음7.5
CVE-2026-48282악용 확인ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Rest…42.4%심각10.0
CVE-2015-0666악용 확인Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) be…40.4%높음7.5
CVE-2024-55550랜섬웨어 악용Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct …38.2%낮음2.7
CVE-2021-38163악용 확인SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker aut…36.0%높음8.8
CVE-2020-8195악용 확인Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21,…33.0%보통6.5
CVE-2018-2380랜섬웨어 악용SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path info…28.9%보통6.6
CVE-2026-20262악용 확인A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authen…28.2%보통6.5
CVE-2019-18187악용 확인Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory tra…25.1%높음7.5
CVE-2025-4632악용 확인Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server versio…24.3%심각9.8
CVE-2026-93616악용 확인A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute a…19.7%심각9.8
CVE-2022-20775악용 확인A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain eleva…12.5%높음7.8
CVE-2022-41328악용 확인A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in For…10.7%높음7.1
CVE-2022-26500랜섬웨어 악용Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote auth…5.8%높음8.8
CVE-2020-1631악용 확인A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Auth…4.8%심각9.8
CVE-2013-3993랜섬웨어 악용IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and direct…4.8%보통6.5
CVE-2025-2749악용 확인An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to …4.1%높음7.2
CVE-2019-7483악용 확인In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows …4.0%높음7.5
CVE-2024-7262악용 확인Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to…2.9%심각9.3
CVE-2024-11667랜섬웨어 악용A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.0…2.9%심각9.8
CVE-2026-59310랜섬웨어 악용VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with netwo…2.6%심각9.8
CVE-2026-104286악용 확인An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo…2.2%심각9.8
CVE-2026-34909악용 확인A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS de…1.8%심각10.0
CVE-2026-66384악용 확인An authenticated user may write data outside the intended Docker cache path under specific remote-repository c…0.7%보통5.3
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticate…1.3%심각9.8
CVE-2026-91989atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that all…1.3%높음8.7
CVE-2025-57231Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose …1.3%높음7.5
CVE-2026-55224MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operatio…1.2%높음8.7
CVE-2026-100372ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allo…1.1%높음8.6
CVE-2026-76431A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco I…1.1%보통4.9
CVE-2026-77621Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its …1.1%심각9.3
CVE-2026-15095The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordP…1.1%보통4.9
CVE-2026-80155Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware version…1.0%심각10.0
CVE-2026-78461Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an…1.0%높음7.4
CVE-2026-93643When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing s…1.0%심각9.8
CVE-2026-54629Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQ…1.0%높음7.5
CVE-2017-20284Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remot…1.0%높음8.7
CVE-2026-100520Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file end…0.9%높음8.7
CVE-2026-14323The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Tr…0.9%높음7.5
CVE-2026-70200Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an u…0.9%심각10.0
CVE-2026-76433A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unau…0.9%보통5.3
CVE-2026-89040Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST…0.9%심각9.3
CVE-2026-81547IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary c…0.9%높음8.8
CVE-2026-75098The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and …0.9%높음7.5
CVE-2026-93992Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attacker…0.9%높음7.0
CVE-2026-87115The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion du…0.9%심각9.1
CVE-2026-76432A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authentica…0.9%보통4.9
CVE-2026-84086IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to…0.9%높음7.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.