CWE-295 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-295 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2020-0601A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve …89.4%높음8.1● 실제 악용이 확인됨CVE-2022-26923Active Directory Domain Services Elevation of Privilege Vulnerability83.5%높음8.8● 실제 악용이 확인됨CVE-2023-41991A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 an…13.4%보통5.5● 실제 악용이 확인됨CVE-2022-20703Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could…9.2%높음8.0● 실제 악용이 확인됨CVE-2026-85102Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway…7.5%심각9.8● 실제 악용이 확인됨CVE-2023-20963In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege…1.5%높음7.8CVE-2026-86131A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handl…0.3%심각9.2CVE-2026-84081IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due …0.3%높음8.1
전체 목록
113건
CVE-2026-100665Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QU…0.3%높음8.7
CVE-2026-93302MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected build…0.3%높음8.3
CVE-2026-63374AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or as…0.3%심각9.3
CVE-2026-90623A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect …0.3%낮음2.9
CVE-2026-103921GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the ex…0.3%높음7.4
CVE-2026-85086Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache…0.3%보통6.9
CVE-2026-52724Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to…0.2%보통5.8
CVE-2026-61668DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.2…0.2%높음8.1
CVE-2026-67231RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The…0.2%심각9.1
CVE-2026-103602Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp b…0.2%높음8.2
CVE-2026-97687urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hos…0.2%높음7.6
CVE-2026-18173IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive…0.2%낮음3.7
CVE-2026-67404RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Whe…0.2%심각9.2
CVE-2026-63577Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.Within…0.2%높음8.2
CVE-2026-93291Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle atta…0.2%심각9.3
CVE-2026-82180In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentica…0.2%심각9.5
CVE-2026-84975PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSS…0.2%높음7.4
CVE-2026-78234A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the …0.2%심각9.9
CVE-2026-63576Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Ca…0.2%높음8.2
CVE-2026-100835Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestati…0.2%심각9.1
CVE-2026-83964Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of…0.2%보통6.2
CVE-2026-85088Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift. Both librar…0.2%보통6.9
CVE-2026-85087Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings. T…0.2%보통6.9
CVE-2026-84197In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-…0.2%심각9.2
CVE-2026-101916@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.…0.2%높음7.4
CVE-2026-89135A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassi…0.2%보통6.3
CVE-2026-81871OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplo…0.2%보통6.3
CVE-2026-15911Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensit…0.2%높음7.4
CVE-2026-79637Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%높음7.7
CVE-2026-86889A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macO…0.2%보통4.8
CVE-2026-90651Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TL…0.2%높음8.1
CVE-2026-50166Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to…0.2%보통5.5
CVE-2026-78492Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%높음7.4
CVE-2026-80125Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통5.9
CVE-2026-71885In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bin…0.2%심각9.2
CVE-2026-93600rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alph…0.2%낮음2.1
CVE-2026-93601rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alph…0.2%낮음2.1
CVE-2026-89102In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP …0.2%높음8.3
CVE-2026-100551OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI.…0.2%심각9.0
CVE-2026-84736In the current development version of Eclipse aeriOS, for which no official release has yet been published, th…0.2%높음8.3
CVE-2026-78491Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%높음8.2
CVE-2026-81868Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native…0.2%보통6.5
CVE-2026-71889In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKI…0.2%높음8.7
CVE-2026-80443Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in t…0.2%높음7.4
CVE-2026-78494Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%높음7.4
CVE-2026-80164Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%높음7.4
CVE-2026-79644Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%높음7.4
CVE-2026-87608Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker lev…0.1%미평가
CVE-2026-84961undici's BalancedPool constructor passes its entire options object through an internal deep-clone that seriali…0.1%높음7.4
CVE-2026-87551Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leve…0.1%미평가
CVE-2026-92868An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attac…0.2%보통6.9
CVE-2026-15937Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID …0.1%보통5.3
CVE-2026-79734Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.9
CVE-2026-90647ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate …0.1%심각9.1
CVE-2026-80122Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%높음7.3
CVE-2026-89133wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to …0.1%보통6.3
CVE-2026-78483Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.9
CVE-2026-78489Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.9
CVE-2026-9036IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificat…0.1%보통5.9
CVE-2026-89134A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the S…0.1%보통6.3
CVE-2026-79691Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%높음7.3
CVE-2026-81447Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation …0.1%보통6.8
CVE-2026-102508Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of A…0.1%심각9.2
CVE-2026-79690Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%낮음3.7
CVE-2026-79736Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%낮음3.7
CVE-2026-79729Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%낮음3.7
CVE-2026-65129NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper cer…0.1%보통6.7
CVE-2026-65118NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper cer…0.1%높음7.5
CVE-2026-77707Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Mid…0.1%보통5.9
CVE-2026-102671The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.0.1%보통6.9
CVE-2026-13327Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and e…0.1%미평가
CVE-2026-84465Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the dig…0.1%높음7.1
CVE-2026-102668The Joyland AI app accepts any TLS certificates from any server without validation.0.1%보통6.9
CVE-2026-82157Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation …0.1%높음8.3
CVE-2026-79642Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.6
CVE-2026-79732Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificat…0.1%낮음3.7
CVE-2026-40539An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2…0.1%높음7.1
CVE-2026-87571Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker le…0.1%미평가
CVE-2026-86474The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in …0.1%높음7.7
CVE-2026-100701Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, wh…0.1%보통6.0
CVE-2026-86185Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remot…0.1%높음8.6
CVE-2026-87733An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P38…0.1%보통6.2
CVE-2026-85525Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS…0.1%높음7.4
CVE-2026-79639Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%높음7.6
CVE-2026-79967Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.6
CVE-2026-84850Improper certificate validation in the shared HTTP client used by synchronization and integration features in …0.1%미평가
CVE-2026-20500In Modem, there is a possible system crash due to improper input validation. This could lead to local denial o…0.1%보통5.5
CVE-2026-87872A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection.…0.1%보통6.8
CVE-2026-90452Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and crede…0.1%보통6.0
CVE-2026-20323A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Sec…0.1%높음8.3
CVE-2026-85221MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer …0.1%높음7.6
CVE-2026-73587Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certifica…0.1%보통6.8
CVE-2026-73594Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contai…0.1%보통6.4
CVE-2026-91812A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass cer…0.1%높음7.9
CVE-2026-79975Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.5
CVE-2026-10726Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privi…0.1%보통6.8
CVE-2026-105223maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and p…심각9.1
CVE-2026-105222The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default b…심각9.1
CVE-2026-105221The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path at…심각9.1
CVE-2026-105218gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing…심각9.1
CVE-2026-105217Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart requ…낮음2.3
CVE-2026-105216go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers …심각9.1
CVE-2018-20135Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installatio…높음8.1
CVE-2018-3927An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the S…보통5.9
CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.…높음8.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.