$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-346 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-346

전체 목록

44건

CVE-2026-92701trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS)…0.3%심각9.1
CVE-2026-77339Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP …0.3%보통5.1
CVE-2026-92359A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create…0.2%낮음2.3
CVE-2026-102878mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows…0.2%높음8.6
CVE-2026-55837dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper i…0.2%보통6.8
CVE-2026-102675Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.2%높음7.4
CVE-2026-103922Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3…0.2%심각9.3
CVE-2026-82438Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's…0.2%높음8.1
CVE-2026-57112PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.…0.2%높음8.3
CVE-2026-61742DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.2…0.2%심각9.3
CVE-2026-102588A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token …0.2%보통6.5
CVE-2026-77119A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a se…0.2%보통5.9
CVE-2026-100646SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kerne…0.2%높음8.6
CVE-2026-75156Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `i…0.2%심각9.1
CVE-2026-50025Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.…0.2%보통6.9
CVE-2026-92360A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAge…0.2%보통5.3
CVE-2026-85152undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or ded…0.2%높음7.4
CVE-2026-18825An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass ori…0.2%보통5.3
CVE-2026-94485Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev…0.2%보통6.3
CVE-2026-94486Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev …0.2%낮음2.3
CVE-2026-87563Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain c…0.2%보통4.3
CVE-2026-92706Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a websit…0.2%낮음3.4
CVE-2026-75025Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently res…0.1%보통4.7
CVE-2026-91201DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status…0.1%보통5.3
CVE-2026-102673Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.1%높음8.2
CVE-2026-23792An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1…0.1%보통4.0
CVE-2026-12284Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which …0.1%낮음3.7
CVE-2026-91132Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites us…0.1%보통4.3
CVE-2026-85682The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and includin…0.1%높음8.8
CVE-2026-94111Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSock…0.1%보통6.9
CVE-2026-101278A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function open…0.1%낮음2.1
CVE-2026-94243A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This i…0.1%높음7.3
CVE-2026-100598OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versi…0.1%높음7.5
CVE-2026-97155Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser e…0.1%보통6.5
CVE-2026-100642SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth …0.1%높음7.2
CVE-2026-78807An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context…0.1%높음7.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.