CWE-252 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-252 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-67409RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.…0.5%높음8.2CVE-2026-19534undici's WebSocket client crashes the whole Node.js process during the opening handshake when a serv…0.4%높음7.5CVE-2026-18397This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by expl…0.3%심각9.4CVE-2026-86739Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signatur…0.2%낮음2.3CVE-2026-86749Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operation…0.2%높음7.0CVE-2026-85649(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vu…0.2%높음7.9CVE-2026-90648wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily in…0.1%높음7.1CVE-2026-71180Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulner…0.1%높음8.2
전체 목록
10건
CVE-2026-86141xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failur…0.1%낮음2.9
CVE-2026-95316Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to pote…0.1%낮음2.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.