CWE-36 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-36 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-13159Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 Janu…100.0%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2018-20250In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting …96.0%높음7.8● 실제 악용이 확인됨CVE-2024-48248NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via…94.4%높음8.6● 실제 악용이 확인됨CVE-2024-13160Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 Janu…91.2%높음7.5● 실제 악용이 확인됨CVE-2024-13161Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 Janu…90.1%높음7.5CVE-2026-89009WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…0.7%높음8.8CVE-2026-82092IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain se…0.5%높음8.8CVE-2026-88288GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a…0.4%보통6.5
전체 목록
13건
CVE-2026-68487Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.0.4%심각9.9
CVE-2026-69612Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally…0.4%높음7.8
CVE-2026-68896Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privile…0.4%높음7.8
CVE-2025-70820Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.0.2%낮음3.5
CVE-2026-55062uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in …0.2%높음8.4
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.