CWE-400 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-400 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2021-44228Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI …100.0%심각10.0● 실제 악용이 확인됨CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell…100.0%높음7.5● 실제 악용이 확인됨CVE-2023-38180.NET and Visual Studio Denial of Service Vulnerability14.0%높음7.5● 실제 악용이 확인됨CVE-2004-1464Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (vi…4.8%보통5.9● 실제 악용이 확인됨CVE-2020-3566A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR So…3.7%높음8.6● 실제 악용이 확인됨CVE-2020-3569Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco …3.3%높음8.6● 실제 악용이 확인됨CVE-2026-28318SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service wi…1.9%높음7.5● 실제 악용이 확인됨CVE-2026-45498Microsoft Defender Denial of Service Vulnerability1.3%높음7.5
전체 목록
120건
CVE-2026-72923In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microso…1.2%높음7.5
CVE-2026-45769Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …1.2%높음7.5
CVE-2026-75632CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to a…0.9%높음7.5
CVE-2026-96541A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP co…0.8%높음7.5
CVE-2026-57576plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttyp…0.8%보통6.5
CVE-2026-63448Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.7%보통5.9
CVE-2026-93310A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component V…0.7%보통5.5
CVE-2026-57227Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.7%높음7.5
CVE-2026-68496The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLengt…0.7%높음7.5
CVE-2026-68495The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength…0.7%높음7.5
CVE-2026-81876HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior…0.6%높음7.5
CVE-2026-81875HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior…0.6%높음7.5
CVE-2026-88975Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses…0.6%높음7.5
CVE-2026-79651A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core ser…0.6%높음7.5
CVE-2026-89407NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regu…0.6%높음7.5
CVE-2026-63452Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.6%높음7.5
CVE-2026-100650vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented medi…0.6%높음7.1
CVE-2026-94640A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of…0.6%높음7.5
CVE-2026-68537`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tena…0.6%높음7.5
CVE-2026-68523`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tena…0.6%높음7.5
CVE-2026-68497jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalend…0.6%높음7.5
CVE-2026-61814Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a singl…0.6%높음7.5
CVE-2026-61554emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 tra…0.5%높음7.5
CVE-2026-45759Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.6%높음7.5
CVE-2026-54135AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4…0.6%높음7.5
CVE-2026-92114A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file …0.5%보통6.9
CVE-2026-63128RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streama…0.5%높음7.5
CVE-2026-83600Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversi…0.5%보통6.5
CVE-2026-84553A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden …0.5%높음7.5
CVE-2026-92220A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorSchedule…0.5%보통6.9
CVE-2026-92363A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_…0.5%보통5.3
CVE-2026-77791Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message ena…0.5%높음7.5
CVE-2026-93307A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the componen…0.5%낮음2.1
CVE-2026-65115NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled r…0.5%보통6.5
CVE-2026-65112NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled…0.5%보통6.5
CVE-2026-85100A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the funct…0.5%낮음2.1
CVE-2026-92361A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of th…0.5%보통5.3
CVE-2026-76646A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters…0.5%높음7.5
CVE-2026-92362A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/…0.5%보통6.9
CVE-2026-69186c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled A…0.5%보통5.3
CVE-2026-93309A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown function…0.5%낮음2.1
CVE-2026-93308A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functio…0.5%낮음2.1
CVE-2026-101098A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is…0.5%보통5.3
CVE-2026-17463IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Ser…0.5%보통6.5
CVE-2026-89425UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for it…0.5%높음7.5
CVE-2026-50125MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default …0.5%높음7.5
CVE-2026-94449A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like …0.5%높음7.5
CVE-2026-76821OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to …0.5%높음7.1
CVE-2026-87277Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported ve…0.5%높음7.5
CVE-2026-87289Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content)…0.5%높음7.5
CVE-2026-87138Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Acces…0.5%높음7.5
CVE-2026-58483mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilitie…0.5%높음7.5
CVE-2026-69147vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Co…0.5%보통6.5
CVE-2026-69203Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 ena…0.5%높음7.5
CVE-2026-83333Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affe…0.5%높음7.5
CVE-2026-83330Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions th…0.5%높음7.5
CVE-2026-83183Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Su…0.5%높음7.5
CVE-2026-83350Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affe…0.5%높음7.5
CVE-2026-83349Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affe…0.5%높음7.5
CVE-2026-83281Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported ver…0.5%높음7.5
CVE-2026-83280Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Support…0.5%높음7.5
CVE-2026-83228Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Su…0.5%높음7.5
CVE-2026-92596Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that…0.5%높음8.7
CVE-2026-45768Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.5%높음7.5
CVE-2026-86000Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector par…0.4%보통5.3
CVE-2026-87222Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). Th…0.4%높음7.5
CVE-2026-92003Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two …0.4%보통6.9
CVE-2026-73960Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). S…0.4%높음7.5
CVE-2026-69202Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control win…0.4%높음7.5
CVE-2026-92879A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the…0.4%보통5.3
CVE-2026-91777Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear …0.4%높음7.5
CVE-2026-91776TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under …0.4%높음7.5
CVE-2026-45766Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%높음7.5
CVE-2026-71647An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attack…0.4%높음7.5
CVE-2026-45765Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%높음7.5
CVE-2026-79378An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and…0.4%높음7.5
CVE-2026-68904node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua client…0.4%높음7.0
CVE-2021-44320Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attack…0.4%높음7.5
CVE-2026-94408Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocati…0.4%보통4.9
CVE-2026-33625LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.…0.4%높음8.8
CVE-2026-90584A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function…0.4%보통5.5
CVE-2022-51018PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author…0.4%높음7.1
CVE-2026-104861probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg…0.4%높음7.5
CVE-2026-69208Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middlewar…0.4%높음7.5
CVE-2026-90582A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of …0.4%보통5.5
CVE-2026-83459Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Support…0.4%보통5.3
CVE-2026-82300Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Alloc…0.4%보통6.5
CVE-2026-94400Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAP…0.4%보통6.5
CVE-2026-94399Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocati…0.4%보통6.5
CVE-2026-94397Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocati…0.4%보통6.5
CVE-2026-94396Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocati…0.4%보통6.5
CVE-2026-94398Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocati…0.4%보통6.5
CVE-2026-82294Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Alloc…0.4%보통6.5
CVE-2026-86513A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the f…0.4%보통5.5
CVE-2026-86511A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the func…0.4%보통5.5
CVE-2026-86319A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the…0.4%보통5.5
CVE-2026-88798The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value bef…0.4%보통5.3
CVE-2025-71418PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing maliciou…0.4%보통6.9
CVE-2026-56725Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated…0.4%높음8.7
CVE-2026-92356A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponent…0.4%보통5.3
CVE-2026-57224Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%보통6.5
CVE-2026-101906Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypass…0.4%높음8.2
CVE-2026-103760Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthent…0.4%높음8.2
CVE-2026-91941Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrateg…0.4%높음8.7
CVE-2026-104844PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior t…0.4%보통5.9
CVE-2026-84886A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the functi…0.4%보통5.5
CVE-2026-86040libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accep…0.4%높음7.5
CVE-2026-61816zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for re…0.4%높음7.5
CVE-2026-12759IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to un…0.4%보통6.5
CVE-2026-85107A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourc…0.4%보통5.3
CVE-2026-86204PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allo…0.4%높음7.1
CVE-2026-101901Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does…0.4%높음8.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.