CWE-287 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-287 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2023-35078An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2023-35082An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to …100.0%심각9.8● 실제 악용이 확인됨CVE-2024-7593Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or …100.0%심각9.8● 실제 악용이 확인됨CVE-2017-7921An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 14072…100.0%심각9.8● 실제 악용이 확인됨CVE-2021-33044The identity authentication bypass vulnerability found in some Dahua products during the login proce…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2023-46805An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Polic…100.0%높음8.2● 랜섬웨어 캠페인에 사용됨CVE-2022-40684An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2020-0688A remote code execution vulnerability exists in Microsoft Exchange software when the software fails …100.0%높음8.8
전체 목록
120건
CVE-2021-39226악용 확인Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated …99.9%높음7.3
CVE-2025-61882랜섬웨어 악용Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher …99.7%심각9.8
CVE-2021-33045악용 확인The identity authentication bypass vulnerability found in some Dahua products during the login process. Attack…99.6%심각9.8
CVE-2021-32030악용 확인The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_…99.4%심각9.8
CVE-2025-49706랜섬웨어 악용Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing ove…99.1%보통6.5
CVE-2025-61884랜섬웨어 악용Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported…95.9%높음7.5
CVE-2022-23134악용 확인After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, …95.3%보통5.3
CVE-2024-53704랜섬웨어 악용An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to by…95.1%심각9.8
CVE-2013-0625악용 확인Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass a…93.8%심각9.8
CVE-2018-10561악용 확인An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appendin…92.9%심각9.8
CVE-2026-20182악용 확인May 2026: This security advisory provides the details and fix information for a vulnerability that was discove…91.5%심각10.0
CVE-2021-32648악용 확인octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system pa…90.4%심각9.1
CVE-2026-20127악용 확인A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cis…88.5%심각10.0
CVE-2020-8193악용 확인Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 1…88.4%보통6.5
CVE-2015-1187악용 확인The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the…82.9%심각9.8
CVE-2023-27351랜섬웨어 악용This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 2…78.1%높음7.5
CVE-2026-16232악용 확인An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated…78.0%심각9.3
CVE-2020-4427악용 확인IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass sec…70.0%심각9.8
CVE-2023-28461랜섬웨어 악용Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can b…68.1%심각9.8
CVE-2015-7755악용 확인Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 bef…61.1%심각9.8
CVE-2024-8956악용 확인PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The c…58.8%심각9.1
CVE-2019-19006악용 확인Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Contr…55.9%심각9.8
CVE-2021-22893랜섬웨어 악용Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by…47.2%심각10.0
CVE-2020-12812랜섬웨어 악용An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may resu…45.4%심각9.8
CVE-2023-49105악용 확인An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete an…42.9%심각9.8
CVE-2024-37085랜섬웨어 악용VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Director…26.8%높음7.2
CVE-2020-8196악용 확인Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 1…26.3%보통4.3
CVE-2016-7836악용 확인SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authenticat…19.2%심각9.8
CVE-2026-82329악용 확인JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthen…14.1%심각9.8
CVE-2023-20867악용 확인A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacti…13.5%낮음3.9
CVE-2026-42018악용 확인JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous ac…9.8%높음7.5
CVE-2026-50751랜섬웨어 악용A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchan…6.3%심각9.3
CVE-2022-0492악용 확인A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c fu…5.5%높음7.8
CVE-2019-0543랜섬웨어 악용An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "M…4.7%높음7.8
CVE-2025-32975악용 확인Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.…2.5%심각10.0
CVE-2026-49869악용 확인Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilte…2.1%심각10.0
CVE-2026-65400악용 확인An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.…1.7%심각9.8
CVE-2026-59822악용 확인LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM…0.8%높음8.8
CVE-2026-46817악용 확인Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Suppor…0.8%심각9.8
CVE-2026-100886A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affect…0.8%심각9.3
CVE-2026-97864A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlo…0.7%보통5.5
CVE-2026-94493A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown process…0.7%심각9.3
CVE-2026-86293A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is a…0.7%보통5.5
CVE-2026-101077A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component…0.7%심각9.3
CVE-2026-90524A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff1453…0.7%보통5.5
CVE-2026-85984The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authenticat…0.7%심각9.8
CVE-2026-94151A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of th…0.7%보통5.5
CVE-2026-92401A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnera…0.7%보통6.9
CVE-2026-86810A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapa…0.7%보통6.9
CVE-2026-95271A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the functi…0.7%보통5.5
CVE-2026-93559A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2…0.7%보통6.9
CVE-2026-97879A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown…0.6%보통5.5
CVE-2026-69854Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a net…0.6%심각9.0
CVE-2026-97637The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclo…0.6%심각9.8
CVE-2026-75878IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authentica…0.6%심각9.1
CVE-2026-19125The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a…0.6%높음8.1
CVE-2026-90504A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The …0.6%보통5.5
CVE-2026-86808A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the…0.6%보통5.5
CVE-2026-101073A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file …0.6%보통5.5
CVE-2026-97878A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of t…0.6%보통5.5
CVE-2026-76187Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for an…0.6%심각9.8
CVE-2026-75957The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authen…0.6%심각9.8
CVE-2026-88920An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers…0.6%심각9.8
CVE-2026-93960A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file a…0.6%낮음2.1
CVE-2026-86426LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthentic…0.6%심각9.2
CVE-2026-18922A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyru…0.6%심각9.8
CVE-2026-89093The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerab…0.6%보통5.3
CVE-2026-89136When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an uns…0.6%높음8.3
CVE-2026-31377An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthentica…0.5%높음7.5
CVE-2026-86306A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c…0.5%보통5.5
CVE-2026-76009The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in al…0.5%높음8.1
CVE-2026-19607A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the…0.5%보통5.3
CVE-2026-80099Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins …0.5%높음8.8
CVE-2026-86292A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown funct…0.5%보통5.5
CVE-2026-88018rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.5%심각9.8
CVE-2026-47156MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass i…0.5%심각9.3
CVE-2026-75816The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeov…0.5%심각9.8
CVE-2026-93532A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69…0.5%낮음2.1
CVE-2025-43936Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An…0.5%높음8.1
CVE-2026-87184Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). Th…0.5%심각9.8
CVE-2026-83462Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Termi…0.5%심각9.8
CVE-2026-83452Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (componen…0.5%심각9.8
CVE-2026-83037Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%심각9.8
CVE-2026-83327Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalizat…0.5%심각9.8
CVE-2026-83035Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%심각9.8
CVE-2026-83000Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabl…0.5%심각9.8
CVE-2026-83339Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Clien…0.5%심각9.8
CVE-2026-83062Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server…0.5%심각9.8
CVE-2026-83036Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%심각9.8
CVE-2026-83060Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server…0.5%심각9.8
CVE-2026-83059Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server…0.5%심각10.0
CVE-2026-83094Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmod…0.5%심각9.8
CVE-2026-83066Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server…0.5%심각9.8
CVE-2026-83061Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server…0.5%심각9.8
CVE-2026-73961Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported v…0.5%심각9.8
CVE-2026-83100Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmod…0.5%심각9.8
CVE-2026-82995Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Central…0.5%심각9.8
CVE-2026-83095Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmod…0.5%심각9.8
CVE-2026-83042Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). S…0.5%심각9.8
CVE-2026-82994Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Central…0.5%심각9.8
CVE-2026-73956Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppor…0.5%심각9.8
CVE-2026-100746A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the…0.5%보통5.5
CVE-2026-86300A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the compone…0.5%보통5.5
CVE-2026-101004A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue …0.5%보통6.9
CVE-2026-95676A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor a…0.5%높음7.4
CVE-2026-94276Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote int…0.5%보통5.1
CVE-2026-94606authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email auth…0.5%높음8.9
CVE-2026-14378The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Ta…0.5%심각9.8
CVE-2026-90961The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Bot…0.5%심각9.3
CVE-2026-54176backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…0.5%보통6.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.