CWE-425 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-425 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-45195Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: b…100.0%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2021-26085Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources…99.9%보통5.3CVE-2026-40532A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager…0.4%보통6.5CVE-2026-102583A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor…0.2%낮음2.7CVE-2026-80275Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to e…0.2%높음8.8CVE-2026-102584A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user c…0.2%보통4.3CVE-2026-102582A flaw was found in Moodle. The manual enrolment management page did not properly check whether the …0.2%보통4.3CVE-2026-36453Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be…0.2%높음7.4
전체 목록
9건
CVE-2026-105046Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.0.2%보통4.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.