$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-345 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-345

전체 목록

81건

CVE-2026-80172Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.3%심각9.8
CVE-2026-92161FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Pr…0.3%심각9.8
CVE-2026-94612authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML So…0.3%높음7.4
CVE-2026-94455An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any sess…0.3%높음7.1
CVE-2026-54581mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmpo…0.2%높음8.3
CVE-2026-89238WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted …0.2%심각9.1
CVE-2026-26950Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity …0.2%높음8.1
CVE-2026-63405AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, t…0.2%보통5.9
CVE-2026-73316XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows …0.2%높음8.7
CVE-2026-73437On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an …0.2%보통6.5
CVE-2026-63127RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementa…0.2%높음8.2
CVE-2026-54608MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app…0.2%높음7.1
CVE-2026-19941An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which coul…0.2%보통5.9
CVE-2026-102831JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb…0.2%높음8.1
CVE-2026-54167Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior…0.2%높음8.2
CVE-2026-86039libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-s…0.2%높음8.2
CVE-2026-81630The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The up…0.2%심각9.2
CVE-2026-85429MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than valida…0.2%높음8.7
CVE-2026-88592kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint …0.2%심각9.1
CVE-2026-92360A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAge…0.2%보통5.3
CVE-2026-49450Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prio…0.2%높음7.1
CVE-2026-100872Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing u…0.2%높음8.7
CVE-2026-85435MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle …0.2%심각9.3
CVE-2026-85434MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge…0.2%심각9.3
CVE-2026-104422The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinba…0.2%높음8.7
CVE-2026-61591djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance.…0.2%높음8.1
CVE-2026-73435On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specia…0.2%높음7.0
CVE-2026-86038libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossip…0.2%높음7.5
CVE-2026-85621LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feish…0.2%보통6.9
CVE-2026-45057matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in t…0.2%보통4.9
CVE-2026-89251AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_S…0.2%높음7.1
CVE-2026-92400The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming p…0.2%보통5.3
CVE-2026-13720An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app…0.2%보통5.4
CVE-2026-102267PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected b…0.2%높음7.4
CVE-2026-85515In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error report…0.2%높음8.2
CVE-2026-84906The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order i…0.1%보통5.3
CVE-2026-73177Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the…0.1%높음8.6
CVE-2026-54579mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies with…0.1%낮음2.3
CVE-2026-92422The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concate…0.2%보통6.5
CVE-2026-55174UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, com…0.1%보통5.9
CVE-2026-53728Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the exter…0.1%높음7.1
CVE-2026-54586mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index…0.1%보통6.0
CVE-2026-85641The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which…0.1%보통4.3
CVE-2026-73450On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attac…0.1%높음7.0
CVE-2026-57122PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify …0.1%높음8.6
CVE-2026-77955In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-ch…0.1%보통4.4
CVE-2026-102140An authenticated administrator could initiate an administrative import using a file whose contents were not fu…0.1%보통4.9
CVE-2026-102275PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from…0.1%보통6.5
CVE-2026-85288Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortc…0.1%보통6.7
CVE-2026-88819In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer…0.1%보통6.3
CVE-2026-84767Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.0.1%보통5.3
CVE-2026-101278A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function open…0.1%낮음2.1
CVE-2026-103878Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extende…0.1%미평가
CVE-2026-104419Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then …0.1%보통6.3
CVE-2026-85008undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is …0.1%낮음3.7
CVE-2026-86809The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority ret…0.1%보통5.3
CVE-2026-83537The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually …0.1%보통5.3
CVE-2026-84043The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenti…0.1%보통5.3
CVE-2026-82215The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity…0.1%보통5.9
CVE-2026-78296Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity …0.1%보통5.3
CVE-2026-89411The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belon…0.1%보통5.3
CVE-2026-92996The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a paymen…0.1%보통5.3
CVE-2026-87978The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch …0.1%보통5.3
CVE-2026-92138The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `o…0.1%보통4.2
CVE-2026-54174melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, correspon…0.1%높음8.3
CVE-2026-89050The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with…0.1%보통4.3
CVE-2026-91017The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity o…0.1%낮음3.7
CVE-2026-81338The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HT…0.1%보통4.6
CVE-2026-102677Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 4…0.1%높음7.8
CVE-2026-71887In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing …0.1%높음8.2
CVE-2026-102711Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module ob…0.1%보통5.7
CVE-2026-105161A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of…보통6.9
CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.…높음8.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.