$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-306 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-306

CWE-306 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

9.8LACWE-306● 랜섬웨어 캠페인에 사용됨CVE-2025-3248Langflow · LangflowLangflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endp…100.0%심각9.87.5ORCWE-306● 랜섬웨어 캠페인에 사용됨CVE-2017-10271Oracle · WebLogic ServerVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS…100.0%높음7.59.8JECWE-288● 랜섬웨어 캠페인에 사용됨CVE-2023-42793JetBrains · TeamCityIn JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was p…100.0%심각9.89.8F5CWE-306● 랜섬웨어 캠페인에 사용됨CVE-2022-1388F5 · BIG-IPOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p…100.0%심각9.87.5ORCWE-502● 실제 악용이 확인됨CVE-2023-21839Oracle · WebLogic ServerVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S…99.9%높음7.59.3PACWE-306● 랜섬웨어 캠페인에 사용됨CVE-2024-0012Palo Alto Networks · PAN-OSAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker w…99.9%심각9.39.8ZOCWE-306● 실제 악용이 확인됨CVE-2021-37415Zoho · ManageEngine ServiceDesk Plus (SDP)Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a…99.8%심각9.89.8APCWE-306● 실제 악용이 확인됨CVE-2020-13927Apache · Airflow's Experimental APIThe previous default setting for Airflow's Experimental API was to allow all API requests without au…99.8%심각9.8

전체 목록

120건

CVE-2025-32433악용 확인Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5…98.8%심각10.0
CVE-2026-41940랜섬웨어 악용cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allo…98.5%심각9.3
CVE-2025-0108악용 확인An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with ne…98.5%높음8.8
CVE-2022-21587랜섬웨어 악용Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component:…98.3%심각9.8
CVE-2021-39144악용 확인XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerabilit…98.1%높음8.5
CVE-2020-6207악용 확인SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not …98.1%심각9.8
CVE-2025-34028악용 확인The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that repre…97.6%심각9.3
CVE-2019-9082악용 확인ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution v…97.4%높음8.8
CVE-2026-20253악용 확인In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could cr…96.9%심각9.8
CVE-2023-46747랜섬웨어 악용Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access…96.5%심각9.8
CVE-2021-35587악용 확인Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Sup…96.3%심각9.8
CVE-2024-47575악용 확인A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiM…94.8%심각9.8
CVE-2020-6287악용 확인SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authen…94.7%심각10.0
CVE-2025-4008악용 확인The Meteobridge web interface let meteobridge administrator manage their weather station data collection and a…93.7%높음8.7
CVE-2023-36846악용 확인A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows…93.5%보통5.3
CVE-2021-44077악용 확인Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus bef…93.3%심각9.8
CVE-2020-10148악용 확인The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execu…92.0%심각9.8
CVE-2024-11680악용 확인ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthen…91.7%심각9.8
CVE-2024-5910악용 확인Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admi…91.7%심각9.3
CVE-2020-3952악용 확인Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Plat…90.4%심각9.8
CVE-2025-61757악용 확인Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Suppo…88.6%심각9.8
CVE-2026-24423랜섬웨어 악용SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnera…88.2%심각9.3
CVE-2026-1603악용 확인An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated at…87.9%높음7.5
CVE-2022-26143악용 확인The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through …87.3%심각9.8
CVE-2024-51567랜섬웨어 악용upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attacker…86.6%심각9.8
CVE-2023-36847악용 확인A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows …83.5%보통5.3
CVE-2022-24990랜섬웨어 악용TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending …83.0%높음7.5
CVE-2023-27532랜섬웨어 악용Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration…81.3%높음7.5
CVE-2023-28461랜섬웨어 악용Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can b…68.1%심각9.8
CVE-2024-8956악용 확인PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The c…58.8%심각9.1
CVE-2022-23227악용 확인NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be…48.5%심각9.8
CVE-2026-39987악용 확인marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal W…37.9%심각9.3
CVE-2026-33017악용 확인Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the…24.8%심각9.3
CVE-2020-24363악용 확인TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to sub…20.7%높음8.8
CVE-2019-5591랜섬웨어 악용A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to i…18.4%보통6.5
CVE-2010-5326악용 확인The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require …17.8%심각10.0
CVE-2022-26925악용 확인Windows LSA Spoofing Vulnerability10.5%보통5.9
CVE-2026-35273랜섬웨어 악용Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Enviro…9.4%심각9.8
CVE-2022-26501랜섬웨어 악용Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).4.1%심각9.8
CVE-2026-67277악용 확인RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentic…1.6%높음8.8
CVE-2026-72529악용 확인A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to …1.5%심각9.3
CVE-2023-36851악용 확인A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows…1.1%보통5.3
CVE-2026-56164악용 확인Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to…1.0%심각9.8
CVE-2026-59822악용 확인LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM…0.8%높음8.8
CVE-2026-46817악용 확인Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Suppor…0.8%심각9.8
CVE-2025-48572악용 확인In multiple locations, there is a possible way to launch activities from the background due to a permissions b…0.3%높음7.8
CVE-2026-75791Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass…1.7%높음8.6
CVE-2026-75825ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were v…1.1%높음8.8
CVE-2026-93839LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint …1.0%심각9.3
CVE-2026-57131PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jo…1.0%심각9.8
CVE-2026-85889Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate pr…0.9%심각10.0
CVE-2026-57127PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAut…0.9%심각9.8
CVE-2026-75430PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint …0.9%심각9.8
CVE-2026-105105CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait…0.8%심각9.8
CVE-2026-82967IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated rem…0.8%심각9.8
CVE-2026-54767WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_…0.8%심각9.1
CVE-2026-97864A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlo…0.7%보통5.5
CVE-2026-94493A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown process…0.7%심각9.3
CVE-2026-86293A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is a…0.7%보통5.5
CVE-2026-90944Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing …0.7%높음8.8
CVE-2026-101077A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component…0.7%심각9.3
CVE-2026-81475Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critic…0.7%높음8.1
CVE-2026-90524A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff1453…0.7%보통5.5
CVE-2026-54460OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Pr…0.7%심각9.8
CVE-2026-54670WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web…0.7%심각9.1
CVE-2026-73173Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the e…0.7%높음8.8
CVE-2026-94151A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of th…0.7%보통5.5
CVE-2026-9317Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unau…0.7%심각9.2
CVE-2026-102811Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content…0.7%높음8.7
CVE-2026-69415Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate p…0.7%보통6.8
CVE-2026-57124PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mc…0.6%심각9.8
CVE-2026-93559A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2…0.7%보통6.9
CVE-2026-97879A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown…0.6%보통5.5
CVE-2026-90504A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The …0.6%보통5.5
CVE-2026-86808A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the…0.6%보통5.5
CVE-2026-97878A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of t…0.6%보통5.5
CVE-2026-70352Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate p…0.6%심각10.0
CVE-2026-86242Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthe…0.6%높음8.1
CVE-2026-54446NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the softwa…0.6%높음8.1
CVE-2026-48005Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.6…0.6%높음7.5
CVE-2026-77254MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.6%심각9.1
CVE-2026-86184Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that…0.6%심각9.3
CVE-2026-86121Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is…0.6%심각9.3
CVE-2026-84075IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing…0.6%심각9.9
CVE-2026-8065An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life ve…0.6%심각9.1
CVE-2026-88263XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may …0.6%높음8.7
CVE-2026-57443SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to…0.6%높음7.5
CVE-2026-93960A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file a…0.6%낮음2.1
CVE-2026-13249An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interfa…0.6%심각9.8
CVE-2026-54504MCP Documentation Server is a local-first document management and semantic search server for AI coding agents.…0.6%높음8.8
CVE-2026-103244ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore comma…0.6%심각9.3
CVE-2026-79954NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. …0.6%높음8.7
CVE-2026-57967An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing sess…0.6%심각9.8
CVE-2026-92729SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoint…0.5%높음8.8
CVE-2026-85428MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP serv…0.5%심각9.3
CVE-2026-85424MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to c…0.5%심각9.3
CVE-2026-86124AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all …0.5%심각9.3
CVE-2026-82042UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain f…0.5%심각9.3
CVE-2026-92625Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/l…0.5%높음7.5
CVE-2026-88259CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An …0.5%높음8.7
CVE-2026-103270LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authenticat…0.5%높음8.7
CVE-2026-86292A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown funct…0.5%보통5.5
CVE-2026-88018rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.5%심각9.8
CVE-2026-85663Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through geta…0.5%심각9.3
CVE-2026-54618Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an…0.5%심각9.4
CVE-2026-87184Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). Th…0.5%심각9.8
CVE-2026-83462Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Termi…0.5%심각9.8
CVE-2026-83452Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (componen…0.5%심각9.8
CVE-2026-103765Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /met…0.5%높음8.8
CVE-2026-83037Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%심각9.8
CVE-2026-83327Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalizat…0.5%심각9.8
CVE-2026-83035Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). …0.5%심각9.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.