CWE-290 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-290 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-4358In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthentica…97.5%심각9.8● 실제 악용이 확인됨CVE-2022-24112An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Adm…96.1%심각9.8● 실제 악용이 확인됨CVE-2022-23131In the case of instances where the SAML SSO authentication is enabled (non-default), session data ca…95.7%심각9.8● 실제 악용이 확인됨CVE-2024-54085AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely t…60.7%심각10.0● 실제 악용이 확인됨CVE-2023-50224TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vul…15.6%보통6.5CVE-2026-69843Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate pri…0.9%심각10.0CVE-2026-76949Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacke…0.8%심각9.1CVE-2026-94422An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an a…0.7%높음8.7
전체 목록
72건
CVE-2026-77903Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges…0.7%심각9.0
CVE-2026-76423A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker…0.5%심각10.0
CVE-2026-85751Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mai…0.6%심각9.8
CVE-2026-87785Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for inter…0.5%심각9.1
CVE-2026-92899Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It st…0.5%보통4.8
CVE-2026-59157webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP reques…0.5%보통6.5
CVE-2026-55210Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prio…0.5%높음7.4
CVE-2026-21391An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or pro…0.4%심각9.5
CVE-2026-94416An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an …0.5%보통6.8
CVE-2026-62108Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.0.4%심각9.8
CVE-2026-91039Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who oper…0.4%심각9.1
CVE-2026-101280A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendma…0.4%보통5.5
CVE-2026-104445YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bi…0.4%높음8.8
CVE-2026-61682kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workload…0.4%심각9.9
CVE-2026-86478In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed …0.4%심각9.8
CVE-2026-84186Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which a…0.3%보통6.9
CVE-2026-86863pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or re…0.3%심각9.3
CVE-2026-92929OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an a…0.4%보통5.3
CVE-2026-77089Command Center API contained an authentication bypass issue affecting privilege management. Software customers…0.3%심각9.3
CVE-2026-18065IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive informa…0.3%보통5.3
CVE-2026-92395@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse prox…0.3%심각9.1
CVE-2026-40854WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. Th…0.3%높음8.7
CVE-2025-68624N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated …0.3%보통4.3
CVE-2026-89022BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation th…0.3%심각9.1
CVE-2026-63329Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request i…0.3%보통4.9
CVE-2026-49446Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, a…0.3%보통6.1
CVE-2026-85432MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authent…0.3%높음8.8
CVE-2026-97274Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.0.3%심각9.8
CVE-2026-15640Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.0.3%심각9.5
CVE-2026-100390Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting…0.3%심각9.1
CVE-2026-90447A routing rule selects between two different authentication mechanisms for the same downstream service based o…0.3%높음7.1
CVE-2026-82530IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability…0.3%보통6.9
CVE-2026-85511A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-real…0.3%보통4.2
CVE-2026-62759Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over…0.3%높음7.5
CVE-2026-86196Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot…0.3%높음8.7
CVE-2026-88011Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12,…0.2%보통5.3
CVE-2026-45056matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for …0.2%보통6.9
CVE-2026-82180In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentica…0.2%심각9.5
CVE-2026-89327The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is th…0.2%낮음3.8
CVE-2026-103397OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room m…0.2%보통6.3
CVE-2026-88879Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through…0.2%보통5.3
CVE-2026-104733User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary us…0.2%높음7.4
CVE-2026-66674Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.0.2%보통5.6
CVE-2026-104988A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST full…0.2%높음8.1
CVE-2026-62987Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the C…0.2%보통5.8
CVE-2026-96825Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.0.2%보통4.2
CVE-2026-90711proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and …0.2%심각9.1
CVE-2026-93511The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processin…0.2%보통5.3
CVE-2026-97249Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.0.2%보통5.3
CVE-2026-86039libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-s…0.2%높음8.2
CVE-2026-84849Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.0.2%보통6.5
CVE-2026-93538A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster regist…0.2%높음7.1
CVE-2026-20071A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unaut…0.1%낮음3.8
CVE-2026-73449On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature con…0.1%보통5.9
CVE-2026-82563An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation posit…0.1%높음8.4
CVE-2026-63427An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenti…0.1%높음8.5
CVE-2026-88819In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer…0.1%보통6.3
CVE-2026-84465Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the dig…0.1%높음7.1
CVE-2026-105215ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI becaus…심각9.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.