$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-384 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-384

전체 목록

22건

CVE-2026-79312webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly f…0.3%보통6.8
CVE-2026-81181SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication fl…0.3%낮음3.7
CVE-2026-69214Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware…0.3%보통6.8
CVE-2026-92984HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of coo…0.3%높음8.5
CVE-2026-1758Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue a…0.2%높음8.3
CVE-2026-78428For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user recei…0.2%높음8.0
CVE-2026-85238MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow.…0.2%높음7.6
CVE-2026-86279A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0…0.2%낮음2.1
CVE-2026-86674A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02e…0.2%낮음2.1
CVE-2026-104469YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated s…0.2%높음7.6
CVE-2026-76196Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An…0.2%높음7.4
CVE-2026-101268If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attack…0.2%낮음1.7
CVE-2026-61687Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to …0.2%높음7.1
CVE-2026-57179Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipe…0.2%보통4.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.