CWE-367 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-367 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2024-30088Windows Kernel Elevation of Privilege Vulnerability68.2%높음7.0● 실제 악용이 확인됨CVE-2023-35311Microsoft Outlook Security Feature Bypass Vulnerability15.5%높음8.8● 실제 악용이 확인됨CVE-2015-3246libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode p…8.4%보통5.1● 실제 악용이 확인됨CVE-2025-22224VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads t…1.6%높음8.2● 실제 악용이 확인됨CVE-2025-38352In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race betwe…1.3%높음7.8● 실제 악용이 확인됨CVE-2022-48618The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2…0.5%높음7.0CVE-2026-69804Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorize…0.5%높음7.5CVE-2026-86861pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validat…0.5%보통6.0
전체 목록
69건
CVE-2026-82761Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an at…0.4%심각9.1
CVE-2026-77633Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanag…0.4%높음7.1
CVE-2026-77972Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's…0.3%심각9.0
CVE-2026-87433Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromise…0.3%미평가
CVE-2026-63334draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with…0.3%보통6.8
CVE-2024-11222GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.…0.3%보통6.4
CVE-2026-77242MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.3%높음7.5
CVE-2026-91712Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who h…0.3%높음8.3
CVE-2026-91743Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised t…0.3%높음8.3
CVE-2026-79417Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, l…0.3%보통5.3
CVE-2026-85045Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary co…0.2%높음7.5
CVE-2026-53708ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and manage…0.2%보통6.6
CVE-2026-91744Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attac…0.2%보통5.3
CVE-2026-91748Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who h…0.2%높음8.3
CVE-2026-95360Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social …0.2%보통5.3
CVE-2026-95344Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social…0.2%높음8.0
CVE-2026-87523Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging so…0.2%보통5.3
CVE-2026-105130LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register …0.2%보통6.3
CVE-2026-87996Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1,…0.2%높음7.7
CVE-2026-69466Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate p…0.2%높음7.0
CVE-2026-69440Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker…0.2%높음7.0
CVE-2026-69779Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate p…0.2%높음7.0
CVE-2026-68488A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes loca…0.2%심각9.9
CVE-2026-69859Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an a…0.2%높음7.0
CVE-2026-69563Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to…0.2%높음7.0
CVE-2026-93380Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had comprom…0.2%낮음3.1
CVE-2026-78464Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker…0.2%높음7.0
CVE-2026-87517Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveragin…0.2%낮음3.1
CVE-2026-101088Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker …0.2%보통6.0
CVE-2026-88924A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newl…0.2%높음7.0
CVE-2026-91708Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromise…0.2%낮음3.1
CVE-2026-100713Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchron…0.2%높음7.1
CVE-2026-79968Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.9
CVE-2026-82430Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership o…0.1%높음7.8
CVE-2026-18069IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects…0.1%보통6.0
CVE-2026-79730Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.6
CVE-2022-42917In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring …0.1%보통6.7
CVE-2026-82429Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories b…0.1%높음7.8
CVE-2026-45720Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.…0.1%높음7.0
CVE-2026-55567BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning…0.1%높음7.8
CVE-2026-54575mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operatio…0.1%보통5.8
CVE-2026-86805A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (gli…0.1%보통6.3
CVE-2026-45197Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trig…0.1%미평가
CVE-2026-79994The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an autho…0.1%높음8.7
CVE-2026-54587mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_O…0.1%보통5.8
CVE-2026-54576mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_…0.1%보통5.8
CVE-2026-47497NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where …0.1%높음7.8
CVE-2026-76925A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedes…0.1%보통5.8
CVE-2026-87554Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to…0.1%높음8.1
CVE-2026-91813A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between …0.1%높음8.8
CVE-2026-25278Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and …0.1%높음7.8
CVE-2026-86836In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named …0.1%높음8.4
CVE-2026-92369TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the insta…0.1%높음7.3
CVE-2026-40058CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulner…0.1%높음8.8
CVE-2026-104474OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs…0.1%보통5.4
CVE-2026-23786An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 16…0.1%낮음2.8
CVE-2026-100597OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition …0.1%높음8.8
CVE-2026-87457Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to ex…0.1%높음8.1
CVE-2026-18567IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condit…0.1%보통4.4
CVE-2026-58716In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could le…0.1%보통6.7
CVE-2026-105163A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects th…보통6.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.