CWE-307 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-307 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-93650A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability …0.7%낮음2.9CVE-2026-91973Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints t…0.6%높음8.7CVE-2026-77561Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote at…0.6%보통5.3CVE-2026-46649Joplin is an open source note-taking and to-do application that organises notes and lists into noteb…0.6%심각9.1CVE-2026-91972Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints…0.5%높음8.7CVE-2026-37603Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software…0.5%보통6.5CVE-2026-566829Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to re…0.5%보통5.3CVE-2026-6223Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality …0.4%심각9.4
전체 목록
30건
CVE-2026-102334Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated a…0.5%심각9.1
CVE-2026-56592HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to in…0.4%보통6.5
CVE-2026-89174Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection…0.4%높음8.7
CVE-2026-40538An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStati…0.4%낮음3.7
CVE-2026-49470GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time pas…0.4%높음7.7
CVE-2026-85734LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in …0.4%심각9.1
CVE-2026-84461Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step …0.3%보통6.9
CVE-2026-97363The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. T…0.3%높음8.7
CVE-2026-85237A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perfo…0.3%높음8.6
CVE-2026-55795Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in sr…0.3%보통6.9
CVE-2026-78490Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.3%높음7.5
CVE-2026-100501Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the…0.3%높음8.3
CVE-2026-102825Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server:…0.3%낮음3.7
CVE-2026-92583AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically incr…0.2%보통6.9
CVE-2026-100678stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attack…0.2%높음8.3
CVE-2026-86729WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API…0.2%심각9.1
CVE-2026-88770A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solutio…0.2%보통6.5
CVE-2026-58271Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to vers…0.2%보통6.8
CVE-2026-92082By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to…0.2%보통6.3
CVE-2026-86186AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypas…0.2%보통6.3
CVE-2026-20514In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to…0.1%보통4.4
CVE-2026-20512In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to…0.1%미평가
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.