$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-288 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-288

CWE-288 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

9.8JECWE-288● 랜섬웨어 캠페인에 사용됨CVE-2023-42793JetBrains · TeamCityIn JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was p…100.0%심각9.810.0COCWE-288● 랜섬웨어 캠페인에 사용됨CVE-2024-1709ConnectWise · ScreenConnectConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alterna…100.0%심각10.09.8JECWE-288● 랜섬웨어 캠페인에 사용됨CVE-2024-27198JetBrains · TeamCityIn JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was p…99.9%심각9.87.5IVCWE-288● 실제 악용이 확인됨CVE-2025-4427Ivanti · Endpoint Manager Mobile (EPMM)An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior a…99.9%높음7.59.8KECWE-288● 실제 악용이 확인됨CVE-2025-2747Kentico · Xperience CMSAn authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Sta…97.2%심각9.89.3SMCWE-288● 랜섬웨어 캠페인에 사용됨CVE-2026-23760SmarterTools · SmarterMailSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability…96.5%심각9.39.8F5CWE-288● 랜섬웨어 캠페인에 사용됨CVE-2023-46747F5 · BIG-IP Configuration UtilityUndisclosed requests may bypass configuration utility authentication, allowing an attacker with netw…96.5%심각9.89.8FOCWE-288● 랜섬웨어 캠페인에 사용됨CVE-2024-55591Fortinet · FortiOS and FortiProxyAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiO…94.1%심각9.8

전체 목록

46건

CVE-2020-10148악용 확인The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execu…92.0%심각9.8
CVE-2026-20079악용 확인A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an …88.2%심각10.0
CVE-2026-1603악용 확인An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated at…87.9%높음7.5
CVE-2026-24858악용 확인An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet …85.8%심각9.8
CVE-2025-57819악용 확인FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable …85.5%심각10.0
CVE-2025-34026악용 확인The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reve…81.9%심각9.2
CVE-2025-2746악용 확인An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync …73.0%심각9.8
CVE-2023-20269랜섬웨어 악용A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco…25.5%심각9.1
CVE-2026-19490악용 확인Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from…23.2%심각9.3
CVE-2026-18577악용 확인An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Vers…14.6%높음8.2
CVE-2026-18556악용 확인Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authenticati…7.9%높음8.2
CVE-2025-24472랜섬웨어 악용An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 th…7.2%높음8.1
CVE-2026-83527An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthent…1.5%높음8.1
CVE-2026-27546An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in…1.0%심각9.8
CVE-2026-14917A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature …0.7%높음7.7
CVE-2026-62916Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker…0.6%심각9.1
CVE-2026-76169fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the cust…0.5%높음7.5
CVE-2026-62101Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.0.4%심각9.8
CVE-2026-93928Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager…0.4%높음7.3
CVE-2026-81906Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or e…0.3%보통6.3
CVE-2026-79680Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An a…0.3%보통4.5
CVE-2026-62650A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks …0.3%높음8.7
CVE-2026-90481In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypas…0.3%심각9.2
CVE-2026-57134PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai…0.3%높음8.2
CVE-2026-88861Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version availabl…0.3%높음8.7
CVE-2026-77103CommServe contained an authentication bypass issue affecting access authorization and information disclosure. …0.3%높음8.7
CVE-2026-91143goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unaut…0.3%보통6.9
CVE-2026-86084n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC log…0.3%보통6.0
CVE-2026-63493Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an acc…0.3%높음8.6
CVE-2026-81787Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.0.2%보통6.5
CVE-2026-84777Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.0.2%높음7.4
CVE-2026-81783Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.0.2%높음7.1
CVE-2026-81796Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.0.2%높음7.3
CVE-2026-58269Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to vers…0.2%높음8.1
CVE-2026-88260Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of i…0.2%높음8.7
CVE-2026-100261In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update per…0.2%보통5.4
CVE-2026-81868Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…0.2%보통6.5
CVE-2026-88828The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking …0.2%보통5.4
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.