$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-248 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-248

전체 목록

47건

CVE-2022-51014PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handle…0.5%높음7.1
CVE-2026-88411Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4…0.5%높음7.5
CVE-2026-53496ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous fi…0.5%보통5.3
CVE-2026-62985request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP address…0.5%높음7.5
CVE-2026-94646Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of …0.5%높음8.7
CVE-2026-95842Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedExce…0.4%높음8.7
CVE-2026-85494Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, M…0.4%높음8.7
CVE-2026-96277Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. …0.4%높음8.7
CVE-2026-96286Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25…0.4%높음8.2
CVE-2026-96294Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings…0.4%높음8.7
CVE-2026-90440Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in A…0.4%높음8.2
CVE-2026-94642Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.…0.4%높음8.7
CVE-2026-94639improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught ex…0.4%높음8.2
CVE-2026-85493Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thr…0.4%높음8.7
CVE-2026-92081fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route register…0.4%보통5.9
CVE-2026-19534undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server respond…0.4%높음7.5
CVE-2026-54529SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmi…0.4%보통5.3
CVE-2026-102281Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a sing…0.4%높음7.5
CVE-2026-88015rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.4%보통5.3
CVE-2026-85014undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the T…0.4%보통5.9
CVE-2026-92954vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Pro…0.3%심각9.2
CVE-2026-102984Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a requ…0.4%높음8.2
CVE-2022-51009PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when par…0.3%높음8.7
CVE-2026-101101A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.…0.4%보통5.3
CVE-2026-89090An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 …0.3%높음8.2
CVE-2026-92608Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authentic…0.3%높음7.5
CVE-2026-103387A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the fil…0.3%낮음2.1
CVE-2026-82058A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite p…0.3%높음7.1
CVE-2026-100675stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that …0.3%높음7.1
CVE-2026-54541Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm…0.3%낮음3.7
CVE-2026-101918PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get…0.3%보통5.3
CVE-2026-87123hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during outpu…0.3%보통5.9
CVE-2026-85024undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the i…0.3%보통5.9
CVE-2026-100722vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. I…0.3%높음8.9
CVE-2026-61544libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp…0.2%높음8.2
CVE-2026-84947undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a respons…0.2%낮음3.7
CVE-2026-55244ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py e…0.2%보통5.0
CVE-2026-102511Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Ap…0.2%높음8.5
CVE-2026-96274In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during…0.2%높음8.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.