$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-285 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-285

전체 목록

120건

CVE-2026-77239WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation wr…0.5%높음8.1
CVE-2026-61833zot is a container image and artifact registry based on the Open Container Initiative Distribution Specificati…0.5%높음8.1
CVE-2026-84241IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to imprope…0.5%높음8.1
CVE-2026-90566A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77…0.5%보통5.5
CVE-2026-53628GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator …0.5%보통5.9
CVE-2026-16346IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary c…0.5%심각9.9
CVE-2026-63330Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_str…0.4%높음7.7
CVE-2026-85055Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read pe…0.4%높음7.1
CVE-2026-86263A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impac…0.4%보통5.5
CVE-2026-86262A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384…0.4%보통5.5
CVE-2026-86261A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impa…0.4%보통5.5
CVE-2026-95805A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttribute…0.4%보통5.3
CVE-2026-93955A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is t…0.4%낮음2.1
CVE-2026-90521A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70…0.4%낮음2.1
CVE-2026-84076IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions …0.4%높음7.6
CVE-2026-86804A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the functi…0.4%보통6.9
CVE-2026-93954A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the funct…0.4%낮음2.1
CVE-2026-76420A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secu…0.4%심각9.0
CVE-2026-85105A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait…0.4%보통6.9
CVE-2026-92087@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a si…0.4%높음8.1
CVE-2026-90520A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293b…0.4%낮음2.1
CVE-2026-20286A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an a…0.4%보통4.3
CVE-2026-20285A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Pa…0.4%보통4.3
CVE-2026-55775OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capa…0.4%낮음2.3
CVE-2026-54178backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…0.4%높음8.1
CVE-2026-52822Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH …0.4%보통5.3
CVE-2026-94152A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an u…0.4%낮음2.1
CVE-2026-95671In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and e…0.4%보통5.3
CVE-2026-103233A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8f…0.4%낮음2.1
CVE-2026-93547A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an applicati…0.4%보통5.3
CVE-2026-86105An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, …0.4%보통6.0
CVE-2026-54551WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.…0.4%보통4.3
CVE-2026-45052Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SO…0.3%심각9.3
CVE-2026-90517A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown functi…0.3%보통5.5
CVE-2026-86183A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of th…0.3%보통5.5
CVE-2026-85381A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f6…0.3%보통5.5
CVE-2026-67102HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could …0.4%높음8.1
CVE-2026-48717Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeH…0.3%심각9.1
CVE-2026-21587This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Manag…0.3%높음7.1
CVE-2026-21586This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0…0.3%높음7.1
CVE-2026-53952GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS.…0.3%심각9.8
CVE-2026-62286Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go…0.3%보통4.3
CVE-2026-11934IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled t…0.3%높음7.2
CVE-2026-84036IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions …0.3%높음7.4
CVE-2026-49463NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residen…0.3%보통6.5
CVE-2026-90858A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a…0.3%보통5.5
CVE-2026-86277A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0…0.3%보통5.5
CVE-2026-85638A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. Thi…0.3%보통5.5
CVE-2026-85378A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c…0.3%보통5.5
CVE-2026-25254Improper authorization leads to Remote Code Execution via SocketIO interface.0.3%심각9.8
CVE-2026-92799The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorizat…0.3%보통5.3
CVE-2026-55217GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged …0.3%보통5.3
CVE-2026-103532A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAcce…0.3%보통6.9
CVE-2026-97647A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adc…0.3%보통5.5
CVE-2026-49446Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, a…0.3%보통6.1
CVE-2026-75792IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administ…0.3%보통4.3
CVE-2026-97646A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca4…0.3%보통5.5
CVE-2026-90499A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.upda…0.3%낮음2.1
CVE-2026-86212A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the componen…0.3%낮음2.1
CVE-2026-105097A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the f…0.3%낮음2.1
CVE-2026-80436IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of s…0.3%높음8.5
CVE-2026-96762A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function Unm…0.3%보통5.5
CVE-2026-104908MISP contains an improper input validation vulnerability in the decaying model import functionality. The impor…0.3%높음7.1
CVE-2026-52825Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and …0.3%보통5.3
CVE-2026-80378IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of s…0.3%높음8.5
CVE-2026-105096A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the f…0.3%낮음2.1
CVE-2026-96882A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is t…0.3%보통5.5
CVE-2026-96881A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks o…0.3%보통5.5
CVE-2026-96880A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the…0.3%보통5.5
CVE-2026-85241A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV…0.3%보통5.3
CVE-2026-102293A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.a…0.3%보통5.5
CVE-2026-97324A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function u…0.3%보통5.5
CVE-2026-96556A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier…0.3%보통5.5
CVE-2026-104910MISP contains an authorization bypass in the related events listing functionality. When a user requests the li…0.3%보통5.3
CVE-2026-52826Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/…0.3%보통5.3
CVE-2026-79917MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_…0.3%보통6.5
CVE-2026-61604The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the …0.3%심각9.3
CVE-2026-45048Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in th…0.3%높음8.5
CVE-2026-102844A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a…0.3%낮음2.0
CVE-2026-50554Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is…0.2%보통5.3
CVE-2026-44715OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an a…0.2%높음8.7
CVE-2026-105121OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to …0.3%보통6.9
CVE-2026-90697A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part…0.2%낮음2.1
CVE-2026-61837RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 mana…0.2%보통6.3
CVE-2026-102261A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/cont…0.2%낮음2.1
CVE-2026-86283MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query …0.2%높음7.1
CVE-2026-17483IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder…0.2%보통4.3
CVE-2026-90598A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3b…0.2%낮음2.1
CVE-2026-96448A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access m…0.2%보통6.6
CVE-2026-97721A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function …0.2%낮음2.0
CVE-2026-53602nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related auth…0.2%보통6.9
CVE-2026-81569An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user wh…0.2%보통4.3
CVE-2026-97368A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceIm…0.2%낮음2.1
CVE-2026-103659MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the …0.2%높음7.1
CVE-2026-58611Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.0.2%높음7.8
CVE-2026-102846A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8.…0.2%낮음2.0
CVE-2026-10030IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to imprope…0.2%높음7.1
CVE-2026-90935Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver all…0.2%보통5.3
CVE-2026-18175IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper…0.2%높음8.1
CVE-2026-90810A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is th…0.2%낮음2.1
CVE-2026-83805Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic App…0.2%보통6.4
CVE-2026-103858MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a…0.2%보통5.3
CVE-2026-100878A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function …0.2%낮음2.1
CVE-2026-86101An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authen…0.2%높음7.2
CVE-2026-85543Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing auth…0.2%보통4.3
CVE-2026-101006A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/g…0.2%낮음2.1
CVE-2026-105119OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose respons…0.2%높음7.6
CVE-2026-55236langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-a…0.2%보통5.9
CVE-2026-71886In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certifica…0.2%높음8.2
CVE-2026-100897A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f…0.2%보통5.1
CVE-2026-13720An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app…0.2%보통5.4
CVE-2025-71426Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinato…0.1%높음7.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.