$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-347 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-347

CWE-347 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

9.8FOCWE-347● 실제 악용이 확인됨CVE-2025-59718Fortinet · Multiple ProductsA improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7…68.3%심각9.85.5MICWE-347● 실제 악용이 확인됨CVE-2013-3900Microsoft · WinVerifyTrust functionWhy is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Upd…44.6%보통5.57.8MICWE-347● 실제 악용이 확인됨CVE-2020-1464Microsoft · WindowsA spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who …38.9%높음7.89.5SICWE-347● 실제 악용이 확인됨CVE-2026-48558SimpleHelp · SimpleHelpSimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass v…5.7%심각9.54.6IGCWE-347● 실제 악용이 확인됨CVE-2025-47827IGEL · IGEL OSIn IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly ve…4.9%보통4.610.0PACWE-347● 랜섬웨어 캠페인에 사용됨CVE-2020-2021Palo Alto Networks · PAN-OSWhen Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity …4.4%심각10.010.0WSCWE-347● 실제 악용이 확인됨CVE-2026-5430WSO2 · Multiple ProductsThe JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly c…0.6%심각10.07.525CWE-347CVE-2026-57098Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attack…0.6%높음7.5

전체 목록

87건

CVE-2026-56207Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface…0.5%심각9.8
CVE-2026-93657hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::look…0.4%높음8.7
CVE-2026-9832The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of C…0.4%보통5.3
CVE-2026-54155node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken…0.3%높음7.7
CVE-2026-78223Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a call…0.3%보통6.9
CVE-2026-87004Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the …0.3%높음8.1
CVE-2026-18397This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a c…0.3%심각9.4
CVE-2026-28198An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the c…0.3%심각9.4
CVE-2026-59163Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/…0.3%심각9.1
CVE-2026-80098Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate …0.3%심각9.3
CVE-2026-75939A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image…0.3%높음7.4
CVE-2026-89043passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verifi…0.3%심각9.1
CVE-2026-91187Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated…0.3%심각9.3
CVE-2026-89042passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert optio…0.3%심각9.3
CVE-2026-87802Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for O…0.3%심각9.1
CVE-2026-94212Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker …0.3%보통6.4
CVE-2026-86109The VeloCloud Edge software update workflow may accept update bundles without properly validating their signat…0.2%높음7.5
CVE-2026-67276RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an author…0.2%심각9.2
CVE-2026-56727Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inboun…0.2%높음7.1
CVE-2026-54248Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/se…0.2%보통6.5
CVE-2026-80469An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver pac…0.2%높음8.3
CVE-2026-86304MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion …0.2%미평가
CVE-2023-54355PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses…0.2%높음8.7
CVE-2026-85394python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-enc…0.2%심각9.3
CVE-2026-52767YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::ver…0.2%높음8.2
CVE-2026-94368A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multiclo…0.2%높음7.1
CVE-2026-54581mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmpo…0.2%높음8.3
CVE-2026-69646Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perf…0.2%높음8.3
CVE-2026-91191The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as …0.2%높음7.7
CVE-2026-89086In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS…0.2%심각9.1
CVE-2026-61855Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditio…0.2%보통5.3
CVE-2026-85393node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1…0.2%높음8.7
CVE-2026-104437Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, com…0.2%높음8.3
CVE-2026-104435Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent i…0.2%높음8.3
CVE-2026-102268PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py i…0.2%심각9.1
CVE-2026-58200Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.softw…0.2%높음7.1
CVE-2026-95503A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access managemen…0.2%보통6.8
CVE-2026-86326An improper verification of cryptographic signature vulnerability exists in protocol gateways because the devi…0.2%높음8.6
CVE-2026-73784A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowin…0.2%높음8.8
CVE-2026-77105CommServe contained a cryptographic signature verification issue affecting privilege management. Software cust…0.2%높음8.7
CVE-2026-102272PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_…0.2%높음7.4
CVE-2026-80465A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML…0.2%높음8.8
CVE-2026-100293In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmw…0.2%높음8.7
CVE-2026-102273PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.pr…0.2%높음7.4
CVE-2026-102271PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.pre…0.2%높음7.4
CVE-2026-102266PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk…0.2%높음7.4
CVE-2026-71891In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and eve…0.2%높음7.1
CVE-2026-86038libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossip…0.2%높음7.5
CVE-2026-63571Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPath…0.2%높음8.7
CVE-2026-86080n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger …0.2%보통6.3
CVE-2026-42784A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a ke…0.2%높음7.4
CVE-2026-67278MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust stor…0.2%보통6.3
CVE-2026-57178Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` bac…0.2%높음7.4
CVE-2026-103245n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-web…0.2%보통6.9
CVE-2026-97731MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the clien…0.2%높음7.1
CVE-2026-55174UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, com…0.1%보통5.9
CVE-2026-86585The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions p…0.1%높음7.7
CVE-2026-57122PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify …0.1%높음8.6
CVE-2026-102508Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of A…0.1%심각9.2
CVE-2026-18152IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-si…0.1%높음7.4
CVE-2026-85995Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and sign…0.1%높음7.3
CVE-2026-84465Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the dig…0.1%높음7.1
CVE-2026-92718Nuclei versions before 3.11.1 cache template signature verification based only on file modification time witho…0.1%높음7.0
CVE-2026-79970Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.6
CVE-2026-14296When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), ba…0.1%높음7.5
CVE-2026-89169live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism whe…0.1%보통4.1
CVE-2026-85525Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS…0.1%높음7.4
CVE-2026-91814A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF…0.1%보통5.3
CVE-2026-105118OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect…0.1%낮음2.3
CVE-2026-28199An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from th…0.1%보통4.8
CVE-2026-47554NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where improper verificat…0.1%높음7.1
CVE-2026-71887In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing …0.1%높음8.2
CVE-2026-84185A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encrypt…0.1%보통5.9
CVE-2026-87732An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_…0.1%보통6.2
CVE-2025-71422Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent…0.1%보통6.9
CVE-2026-52486An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the…0.1%보통6.6
CVE-2026-97732IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checki…0.1%보통5.1
CVE-2026-94418Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from t…0.1%낮음2.3
CVE-2026-105161A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of…보통6.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.