CWE-269 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-269 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2017-5689An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKU…92.2%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2021-20021A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an adm…88.7%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2016-0151The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and …62.9%높음7.8● 실제 악용이 확인됨CVE-2020-8655An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege esca…60.1%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2019-1405An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) servi…29.9%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2019-1215An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects…19.3%높음7.8● 실제 악용이 확인됨CVE-2013-0643The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows…10.5%높음8.8● 랜섬웨어 캠페인에 사용됨CVE-2019-1388An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not pr…8.6%높음7.8
전체 목록
120건
CVE-2023-28434악용 확인Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use cr…7.9%높음8.8
CVE-2020-3950악용 확인VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon C…7.3%높음7.8
CVE-2002-0367악용 확인smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that conne…4.9%높음7.8
CVE-2026-21533악용 확인Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges lo…4.1%높음7.8
CVE-2024-8068악용 확인Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authe…3.5%보통5.1
CVE-2021-25337악용 확인Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows …2.8%높음7.1
CVE-2023-35674악용 확인In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error …2.6%높음7.8
CVE-2024-49035악용 확인An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elev…1.3%심각9.8
CVE-2021-23874악용 확인Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local use…1.0%높음7.8
CVE-2026-84869악용 확인A condition in the ScreenConnect client may allow files to be transferred and executed through an active remot…0.9%심각9.9
CVE-2026-46817악용 확인Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Suppor…0.8%심각9.8
CVE-2026-12269Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerabilit…7.0%높음8.8
CVE-2026-84830SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticat…1.1%높음8.6
CVE-2026-85979Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_k…1.0%높음8.6
CVE-2026-61781pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_par…0.8%심각9.9
CVE-2026-92619The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inc…0.7%높음7.2
CVE-2026-104018An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 w…0.6%높음8.8
CVE-2026-66818Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network…0.6%높음8.8
CVE-2026-76713A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Succes…0.6%높음7.2
CVE-2026-14281The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPres…0.5%심각9.8
CVE-2026-86553SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime p…0.5%높음8.8
CVE-2026-76801The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPres…0.5%높음8.8
CVE-2026-94609authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with dele…0.5%높음8.8
CVE-2026-92957vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negati…0.5%심각9.4
CVE-2026-90523A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d…0.5%보통5.5
CVE-2026-97644The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Es…0.5%높음8.8
CVE-2026-105126LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated A…0.5%높음8.6
CVE-2026-73470Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Role…0.5%심각9.8
CVE-2026-48826HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/h…0.5%높음8.1
CVE-2026-81445Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vu…0.5%높음7.2
CVE-2026-95687The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via acco…0.5%높음8.8
CVE-2026-101860A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginIn…0.5%높음7.4
CVE-2026-89426The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege …0.5%높음8.8
CVE-2026-65831ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database}…0.4%높음7.7
CVE-2026-76554The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is pe…0.5%높음7.2
CVE-2026-92541The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users cap…0.5%높음7.2
CVE-2026-92540The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote…0.5%높음7.2
CVE-2026-81810The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on …0.5%높음7.2
CVE-2026-17553The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5…0.4%높음7.2
CVE-2026-102676Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.5%높음8.3
CVE-2026-85569The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addres…0.4%높음7.2
CVE-2026-93968A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file bac…0.4%보통5.1
CVE-2026-75160An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoint…0.4%심각9.1
CVE-2026-13355The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to…0.4%심각9.8
CVE-2026-76694A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN…0.4%보통6.6
CVE-2025-71421UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent en…0.4%높음8.6
CVE-2026-54168Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior…0.4%보통6.5
CVE-2026-75983The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable …0.4%높음7.5
CVE-2026-94047A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the func…0.4%낮음2.1
CVE-2026-90787A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Af…0.4%보통5.5
CVE-2026-12793The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in…0.4%심각9.8
CVE-2026-86153A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEn…0.4%심각9.4
CVE-2026-81442Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vu…0.4%높음8.1
CVE-2026-94048A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function …0.4%낮음2.0
CVE-2026-18467The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in al…0.4%심각9.8
CVE-2026-59797Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related ex…0.4%심각9.8
CVE-2026-19807The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in a…0.4%높음8.8
CVE-2026-86814The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownershi…0.4%높음8.1
CVE-2026-85530The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between t…0.4%높음8.1
CVE-2026-17645IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to ga…0.4%심각9.1
CVE-2026-82842The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an …0.4%높음8.1
CVE-2026-94381MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read…0.4%높음8.7
CVE-2026-85154WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expir…0.3%심각9.3
CVE-2026-75927The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin fo…0.3%높음7.2
CVE-2026-78362The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied w…0.3%심각9.8
CVE-2026-86552SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With…0.4%보통5.4
CVE-2026-87068The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere…0.4%보통6.6
CVE-2026-93901The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i…0.3%높음7.3
CVE-2026-102093Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enfo…0.3%높음7.2
CVE-2026-77752The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a …0.3%높음7.2
CVE-2026-19652The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and includin…0.3%심각9.8
CVE-2026-86554SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runti…0.3%보통4.3
CVE-2026-12470The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized m…0.3%높음7.2
CVE-2026-14805The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7…0.3%높음8.8
CVE-2026-77203The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all …0.3%높음8.8
CVE-2026-101086Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, al…0.3%높음7.1
CVE-2026-76731An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unaut…0.3%보통6.5
CVE-2026-15354The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu…0.3%심각9.8
CVE-2026-64753A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 an…0.3%보통6.5
CVE-2026-45801GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated …0.3%보통5.3
CVE-2026-90856A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This…0.3%보통5.5
CVE-2026-100615Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apike…0.3%높음8.7
CVE-2026-68830Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Devic…0.3%보통5.5
CVE-2026-15897The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all v…0.3%높음8.8
CVE-2026-86275A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. …0.3%보통5.5
CVE-2026-17472IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized r…0.3%심각9.6
CVE-2026-92958vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wil…0.3%높음8.4
CVE-2026-85681The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the act…0.3%심각9.8
CVE-2026-15989The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all v…0.3%심각9.8
CVE-2026-86746Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce autho…0.3%높음7.4
CVE-2026-88817An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member…0.3%높음8.7
CVE-2026-92015Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR …0.3%높음8.8
CVE-2026-87998Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1…0.3%높음7.1
CVE-2026-92053Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Fire…0.3%높음8.8
CVE-2026-85514A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of t…0.3%낮음2.1
CVE-2026-97895A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file pac…0.3%낮음2.1
CVE-2026-81431The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced…0.3%높음7.2
CVE-2026-80071The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a m…0.3%높음7.2
CVE-2026-74925The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability setti…0.3%높음7.2
CVE-2026-88891OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level…0.3%높음7.2
CVE-2026-56733Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue conce…0.3%높음8.7
CVE-2026-92017Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firef…0.2%높음8.8
CVE-2026-77968A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, wa…0.2%높음8.2
CVE-2026-85513A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_a…0.2%낮음2.1
CVE-2026-15451The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up t…0.2%높음8.8
CVE-2026-77697Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation Duri…0.2%보통6.3
CVE-2026-14359The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions u…0.2%높음8.8
CVE-2026-81543The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versi…0.2%높음8.8
CVE-2026-92055Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3…0.2%높음8.8
CVE-2026-100620Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its A…0.3%보통5.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.