$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-266 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-266

전체 목록

87건

CVE-2026-100883A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the fi…0.5%낮음2.1
CVE-2026-85400Backend administrators without system maintainer privileges were able to schedule any of the configuration:rea…0.4%높음7.5
CVE-2026-96350Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.0.4%심각9.8
CVE-2026-93968A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file bac…0.4%보통5.1
CVE-2026-94047A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the func…0.4%낮음2.1
CVE-2026-90787A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Af…0.4%보통5.5
CVE-2026-86153A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEn…0.4%심각9.4
CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solu…0.4%높음8.6
CVE-2026-86804A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the functi…0.4%보통6.9
CVE-2026-94048A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function …0.4%낮음2.0
CVE-2026-91930Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tena…0.4%높음7.7
CVE-2026-90520A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293b…0.4%낮음2.1
CVE-2026-84814Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.0.4%심각9.8
CVE-2026-90507A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affe…0.4%낮음2.1
CVE-2026-93504A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[..…0.4%보통5.3
CVE-2026-101053A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the fil…0.4%보통5.5
CVE-2026-97245Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.0.3%높음7.2
CVE-2026-62106Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.0.3%높음8.8
CVE-2026-62102Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.0.3%높음8.8
CVE-2026-86583The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all ve…0.3%높음8.8
CVE-2026-100619Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level secur…0.3%높음8.7
CVE-2026-73461On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authen…0.3%심각9.4
CVE-2026-96815Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.0.3%높음7.2
CVE-2026-103532A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAcce…0.3%보통6.9
CVE-2026-90856A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This…0.3%보통5.5
CVE-2026-94178Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.0.3%높음7.5
CVE-2026-86275A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. …0.3%보통5.5
CVE-2026-90499A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.upda…0.3%낮음2.1
CVE-2026-86212A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the componen…0.3%낮음2.1
CVE-2026-101054A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file…0.3%보통5.5
CVE-2026-96882A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is t…0.3%보통5.5
CVE-2026-96881A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks o…0.3%보통5.5
CVE-2026-96880A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the…0.3%보통5.5
CVE-2026-85241A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV…0.3%보통5.3
CVE-2026-102293A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.a…0.3%보통5.5
CVE-2026-97324A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function u…0.3%보통5.5
CVE-2026-96556A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier…0.3%보통5.5
CVE-2026-85514A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of t…0.3%낮음2.1
CVE-2026-97895A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file pac…0.3%낮음2.1
CVE-2026-102129A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled …0.3%높음7.2
CVE-2026-103752Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.0.3%심각9.8
CVE-2026-102674Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.3%높음8.2
CVE-2026-85401A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown …0.3%낮음2.1
CVE-2026-85513A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_a…0.2%낮음2.1
CVE-2026-103470In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in t…0.3%심각9.3
CVE-2026-96821Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.0.2%보통6.3
CVE-2026-96763A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue af…0.2%낮음2.1
CVE-2026-86482In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation0.2%높음8.8
CVE-2026-86516A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an u…0.2%보통5.1
CVE-2026-86228A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function e…0.2%낮음2.1
CVE-2026-90812A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the fun…0.2%낮음2.1
CVE-2026-103068Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.0.2%높음8.8
CVE-2026-86285A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentCont…0.2%낮음2.1
CVE-2026-81805Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.0.2%높음8.1
CVE-2026-102846A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8.…0.2%낮음2.0
CVE-2026-84756Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.0.2%높음7.1
CVE-2026-90851A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /ad…0.2%낮음2.1
CVE-2026-90810A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is th…0.2%낮음2.1
CVE-2026-90518A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown f…0.2%낮음2.1
CVE-2026-86512A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperati…0.2%낮음2.1
CVE-2026-90487A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality…0.2%낮음2.1
CVE-2026-15140A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under spe…0.2%높음7.7
CVE-2026-103494In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes0.2%보통6.6
CVE-2026-90501A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoCo…0.2%낮음2.1
CVE-2026-103534A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy…0.2%낮음2.1
CVE-2026-81792Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versi…0.2%보통6.5
CVE-2026-101144A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the fi…0.2%낮음2.1
CVE-2026-103286Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications sys…0.2%높음8.5
CVE-2026-84716A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator do…0.2%보통6.6
CVE-2026-93540A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the n…0.2%보통6.5
CVE-2026-94425A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the functio…0.2%심각9.3
CVE-2026-86500In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permission…0.2%보통5.5
CVE-2026-8303Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus…0.1%높음7.8
CVE-2026-90493A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted e…0.1%높음8.5
CVE-2026-63349AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or as…0.1%높음7.0
CVE-2026-77654Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) …0.1%보통6.1
CVE-2026-8148NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHOR…0.1%높음7.8
CVE-2025-58323NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORI…높음7.7
CVE-2025-58322NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORI…높음7.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.