CWE-284 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-284 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2023-27350This vulnerability allows remote attackers to bypass authentication on affected installations of Pap…100.0%심각9.8● 실제 악용이 확인됨CVE-2019-1653A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual G…99.9%높음7.5● 실제 악용이 확인됨CVE-2023-23752An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized…99.8%보통5.3● 실제 악용이 확인됨CVE-2023-29298Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earli…99.8%높음7.5● 실제 악용이 확인됨CVE-2023-38205Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are a…99.7%높음7.5● 실제 악용이 확인됨CVE-2024-27348RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache Huge…99.2%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2012-4681Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update …98.5%심각9.8● 실제 악용이 확인됨CVE-2024-20767ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerabi…98.5%높음7.4
전체 목록
120건
CVE-2023-24489악용 확인A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if explo…97.3%심각9.8
CVE-2023-26360악용 확인Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Impr…97.3%높음8.6
CVE-2013-0422랜섬웨어 악용Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by…97.0%심각9.8
CVE-2011-3544악용 확인Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Upda…96.7%심각9.8
CVE-2025-12480악용 확인Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows acce…95.4%심각9.1
CVE-2022-23134악용 확인After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, …95.3%보통5.3
CVE-2012-1723랜섬웨어 악용Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and ear…93.7%심각9.8
CVE-2016-3427악용 확인Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 …92.3%심각9.8
CVE-2012-5076악용 확인Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and ear…91.3%심각9.8
CVE-2014-3120악용 확인The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers…88.6%높음8.1
CVE-2020-8193악용 확인Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 1…88.4%보통6.5
CVE-2013-2423악용 확인Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and ea…85.2%낮음3.7
CVE-2025-33073악용 확인Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.82.7%높음8.8
CVE-2026-21962악용 확인Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middlew…73.2%심각10.0
CVE-2025-31125악용 확인Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&i…65.2%높음7.5
CVE-2021-22941랜섬웨어 악용Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticat…53.6%심각9.8
CVE-2020-8196악용 확인Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 1…26.3%보통4.3
CVE-2024-40766랜섬웨어 악용An improper access control vulnerability has been identified in the SonicWall SonicOS management access, poten…18.4%심각9.8
CVE-2026-48907악용 확인A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthen…16.2%심각10.0
CVE-2026-34908악용 확인A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in U…15.2%심각10.0
CVE-2015-4902악용 확인Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity …13.6%보통5.3
CVE-2026-35616악용 확인A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenti…9.1%심각9.8
CVE-2019-11634랜섬웨어 악용Citrix Workspace App before 1904 for Windows has Incorrect Access Control.8.0%심각9.8
CVE-2025-59230악용 확인Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate p…2.7%높음7.8
CVE-2020-2506악용 확인The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access con…2.0%심각9.8
CVE-2025-24989악용 확인An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges …1.6%심각9.8
CVE-2026-81963악용 확인Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized at…0.4%높음7.8
CVE-2026-54629Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQ…1.0%높음7.5
CVE-2026-12265Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA fai…0.9%높음8.8
CVE-2026-83944Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a netwo…0.8%심각10.0
CVE-2026-81941IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary …0.8%높음8.8
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticat…0.8%심각9.1
CVE-2026-69268Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne…0.7%높음8.8
CVE-2026-75998ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system re…0.6%높음7.5
CVE-2026-55494Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer…0.6%심각9.8
CVE-2026-86242Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthe…0.6%높음8.1
CVE-2026-55181Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer…0.6%심각9.4
CVE-2026-76709A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Succes…0.6%심각9.8
CVE-2026-94036A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted…0.6%높음7.4
CVE-2026-63695Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unau…0.5%심각9.8
CVE-2026-77487Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.0.5%높음8.8
CVE-2026-73028Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.0.5%높음8.8
CVE-2026-69282Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne…0.5%높음8.8
CVE-2026-69273Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne…0.5%높음8.8
CVE-2026-94148A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of th…0.5%보통5.5
CVE-2026-93971A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file back…0.5%보통6.9
CVE-2026-92927A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown pr…0.5%보통5.5
CVE-2026-90565A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ec…0.5%보통5.5
CVE-2026-86239A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAct…0.5%보통5.5
CVE-2026-85517A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown funct…0.5%보통5.5
CVE-2026-83001Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engi…0.5%심각9.1
CVE-2026-86666A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_jso…0.5%보통5.5
CVE-2026-76441As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gatewa…0.5%심각9.8
CVE-2026-83602Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in s…0.5%보통6.5
CVE-2026-20121A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Fire…0.5%보통5.3
CVE-2026-73959Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppor…0.5%높음8.8
CVE-2026-83032Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%높음8.8
CVE-2026-82999Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabl…0.5%심각9.9
CVE-2026-83039Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppor…0.5%심각9.9
CVE-2026-83033Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%높음8.8
CVE-2026-83031Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%심각9.9
CVE-2026-83008Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Clien…0.5%높음8.8
CVE-2026-82998Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabl…0.5%심각9.9
CVE-2026-82997Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabl…0.5%심각9.9
CVE-2026-90603A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is…0.5%보통6.9
CVE-2026-83006Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Clien…0.5%심각9.1
CVE-2026-83097Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmod…0.5%보통6.5
CVE-2026-95500A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the fun…0.5%보통5.5
CVE-2026-95499A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the funct…0.5%보통6.9
CVE-2026-77169A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace a…0.5%보통6.5
CVE-2026-83017Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distrib…0.4%높음8.8
CVE-2026-73949Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)…0.4%높음8.8
CVE-2026-73948Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppor…0.4%심각9.9
CVE-2026-71047Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported …0.4%높음8.8
CVE-2026-83009Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Clien…0.4%높음8.8
CVE-2026-83005Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Clien…0.4%높음8.8
CVE-2026-83013Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Clien…0.4%높음8.8
CVE-2026-73942Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). S…0.4%높음8.8
CVE-2026-101055A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the fu…0.5%보통5.5
CVE-2026-78313Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.0.5%보통6.5
CVE-2026-100883A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the fi…0.5%낮음2.1
CVE-2026-83019Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supporte…0.4%높음8.1
CVE-2026-20192As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services E…0.4%심각10.0
CVE-2026-95624The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from fron…0.4%보통6.8
CVE-2026-83043Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppor…0.4%심각9.6
CVE-2026-83040Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)…0.4%심각9.6
CVE-2026-79758Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. …0.4%보통5.4
CVE-2026-83051Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). S…0.4%높음7.5
CVE-2026-83093Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmod…0.4%높음8.6
CVE-2026-83023Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). …0.4%높음8.6
CVE-2026-83110Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported vers…0.4%높음7.5
CVE-2026-83075Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manag…0.4%높음7.5
CVE-2026-83034Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.4%높음7.5
CVE-2026-83088Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.…0.4%높음7.7
CVE-2026-83030Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime …0.4%높음8.3
CVE-2026-51916TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledg…0.4%높음7.5
CVE-2026-20120A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Fire…0.4%보통5.8
CVE-2026-90881A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HN…0.4%보통5.5
CVE-2026-83014Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager).…0.4%높음8.1
CVE-2026-73951Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)…0.4%높음8.1
CVE-2026-91164Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API tok…0.4%보통4.3
CVE-2026-12258Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an au…0.4%심각9.2
CVE-2026-97163Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.…0.4%심각10.0
CVE-2026-97161Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0…0.4%심각9.2
CVE-2026-83128Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).…0.4%높음7.5
CVE-2026-83044Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported ver…0.4%높음7.1
CVE-2026-83046Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). S…0.4%높음7.1
CVE-2026-83029Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime …0.4%심각9.6
CVE-2026-76803Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql …0.4%보통5.3
CVE-2026-83123Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations)…0.4%높음7.1
CVE-2026-86272A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.100…0.4%보통5.5
CVE-2026-19290IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote…0.4%높음7.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.