CWE-338 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-338 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-93868Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.pas…0.7%심각9.2CVE-2026-94107NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.ph…0.6%심각9.2CVE-2026-92749SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math…0.5%심각9.2CVE-2026-94456Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically…0.5%심각9.1CVE-2026-92298EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event …0.3%보통6.3CVE-2026-53953GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…0.3%심각9.1CVE-2026-104356PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() …0.3%높음8.2CVE-2026-79901In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Dire…0.3%심각9.9
전체 목록
9건
CVE-2026-9864Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machi…0.1%보통4.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.