CWE-305 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-305 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2025-31161CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crus…100.0%심각9.8● 실제 악용이 확인됨CVE-2026-81578An improper access control vulnerability exists in the web management interface of PaperCut MF and P…85.2%높음8.8● 랜섬웨어 캠페인에 사용됨CVE-2024-37085VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Activ…26.8%높음7.2CVE-2026-86207An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only …0.7%높음7.7CVE-2026-85500Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an …0.5%심각9.1CVE-2026-77185Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.…0.5%심각9.1CVE-2026-94053Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 t…0.4%심각9.1CVE-2026-88837BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, invert…0.3%보통6.5
전체 목록
9건
CVE-2026-59563Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the …0.1%보통4.6
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.