CWE-424 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-424 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-58136Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a …87.8%심각9.8CVE-2026-82754Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server …0.4%보통6.3CVE-2026-86145PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace …0.4%높음8.2CVE-2026-82586Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lu…0.3%높음8.2CVE-2026-93353copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authe…0.3%보통6.0CVE-2026-37008CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstrac…0.1%높음8.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.