$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-434 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-434

CWE-434 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

8.1APCWE-434● 실제 악용이 확인됨CVE-2017-12617Apache · TomcatWhen running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.…100.0%높음8.19.8ADCWE-434● 실제 악용이 확인됨CVE-2018-15961Adobe · ColdFusionAdobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and…100.0%심각9.86.6MICWE-434● 랜섬웨어 캠페인에 사용됨CVE-2021-31207Microsoft · Exchange ServerMicrosoft Exchange Server Security Feature Bypass Vulnerability99.8%보통6.68.1APCWE-434● 랜섬웨어 캠페인에 사용됨CVE-2017-12615Apache · TomcatWhen running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the r…99.6%높음8.19.8SACWE-434● 랜섬웨어 캠페인에 사용됨CVE-2025-31324SAP · NetWeaverSAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowi…99.5%심각9.89.8CLCWE-434● 랜섬웨어 캠페인에 사용됨CVE-2024-50623Cleo · Multiple ProductsIn Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an …98.6%심각9.89.8APCWE-434● 실제 악용이 확인됨CVE-2016-3088Apache · ActiveMQThe Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to uploa…98.5%심각9.89.8WOCWE-434● 실제 악용이 확인됨CVE-2020-25213WordPress · File Manager PluginThe File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload…97.3%심각9.8

전체 목록

120건

CVE-2020-8260악용 확인A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker …96.5%높음7.2
CVE-2024-7399악용 확인Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server versio…91.9%심각9.8
CVE-2026-48908악용 확인A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimate…88.5%심각10.0
CVE-2025-52691랜섬웨어 악용Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files…85.7%심각10.0
CVE-2017-11357랜섬웨어 악용Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUploa…77.7%심각9.8
CVE-2019-8394악용 확인Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary f…63.3%보통6.5
CVE-2021-27860악용 확인A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 1…39.8%높음8.8
CVE-2021-26828악용 확인OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to uplo…39.4%높음8.8
CVE-2020-13671악용 확인Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being inte…35.4%높음8.8
CVE-2024-57968악용 확인Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (…32.3%높음8.8
CVE-2026-56290악용 확인Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla…30.9%심각10.0
CVE-2018-4063악용 확인An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless A…27.1%높음8.8
CVE-2026-48939악용 확인A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachme…20.1%심각10.0
CVE-2021-20022랜섬웨어 악용SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker t…16.5%높음7.2
CVE-2026-56291악용 확인Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla e…14.9%심각10.0
CVE-2021-36741악용 확인An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and …5.0%높음8.8
CVE-2025-2749악용 확인An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to …4.1%높음7.2
CVE-2024-39717악용 확인The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is…4.0%높음7.2
CVE-2024-7694악용 확인ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attac…1.8%높음7.2
CVE-2026-12269Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerabilit…7.0%높음8.8
CVE-2026-84434The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and inclu…3.9%심각9.8
CVE-2026-12264Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover …2.0%높음8.8
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticate…1.3%심각9.8
CVE-2026-82901The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insuffi…1.1%심각9.8
CVE-2026-93031The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are v…1.0%높음8.8
CVE-2026-36467Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote au…1.0%높음7.2
CVE-2026-94104NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint th…1.0%높음8.7
CVE-2026-77929ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achiev…0.9%높음8.7
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload…0.9%심각9.3
CVE-2026-88738Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package…0.9%높음8.8
CVE-2026-102427Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site…0.8%심각10.0
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticat…0.8%심각9.1
CVE-2026-18351The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload …0.8%심각9.8
CVE-2026-54177backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…0.7%보통6.6
CVE-2026-76552The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of f…0.7%높음8.8
CVE-2026-88857Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery e…0.6%심각9.4
CVE-2026-8778The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress …0.6%심각9.8
CVE-2026-87796The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versio…0.6%심각9.8
CVE-2026-93352Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extensio…0.6%심각9.3
CVE-2026-78088The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerabl…0.6%높음8.8
CVE-2026-54675FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the…0.6%높음8.7
CVE-2026-54567Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in…0.6%높음7.5
CVE-2023-54405H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthentica…0.6%심각9.3
CVE-2026-52835Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_con…0.6%높음7.0
CVE-2026-100389GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's att…0.6%심각9.2
CVE-2026-75873The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font…0.6%심각9.8
CVE-2026-13249An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interfa…0.6%심각9.8
CVE-2026-102454EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can…0.6%높음8.6
CVE-2026-94132Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailin…0.6%심각9.5
CVE-2026-87935The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and incl…0.5%높음8.1
CVE-2026-92980HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated ad…0.5%높음8.6
CVE-2026-82187The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of upl…0.5%심각9.8
CVE-2026-56660GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS.…0.5%심각9.1
CVE-2026-42322Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_sta…0.5%심각9.1
CVE-2026-54611InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Ex…0.5%보통5.5
CVE-2026-92820The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions…0.5%높음8.1
CVE-2026-105123W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticat…0.5%높음8.7
CVE-2026-86239A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAct…0.5%보통5.5
CVE-2026-86666A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_jso…0.5%보통5.5
CVE-2026-94383The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating th…0.5%높음8.6
CVE-2026-81650The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensi…0.5%높음7.2
CVE-2026-90603A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is…0.5%보통6.9
CVE-2026-76174Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpo…0.5%심각9.4
CVE-2026-88419An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=…0.5%높음8.8
CVE-2026-26212Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability t…0.5%높음8.6
CVE-2026-95500A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the fun…0.5%보통5.5
CVE-2026-95499A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the funct…0.5%보통6.9
CVE-2026-81402The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or f…0.4%심각9.8
CVE-2026-57581DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-fin…0.4%보통5.3
CVE-2026-84063BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If th…0.4%높음8.5
CVE-2026-84750The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of …0.4%보통6.5
CVE-2026-13248An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface …0.4%높음8.8
CVE-2026-18143The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all version…0.4%심각9.8
CVE-2026-86272A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.100…0.4%보통5.5
CVE-2026-12483The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and in…0.4%높음7.5
CVE-2026-70356The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to uplo…0.4%심각9.4
CVE-2026-84171The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded fi…0.4%심각9.8
CVE-2026-103474yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing au…0.4%높음8.7
CVE-2026-86305A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a…0.4%보통5.5
CVE-2026-102130Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowe…0.4%높음7.2
CVE-2026-81236Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Danger…0.4%높음8.6
CVE-2026-81240Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Danger…0.4%높음8.6
CVE-2026-81239Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Danger…0.4%높음8.6
CVE-2026-71805An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote at…0.4%심각9.8
CVE-2026-104471YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to wr…0.4%높음8.6
CVE-2026-82793Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / U…0.4%높음8.6
CVE-2026-82780Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted fi…0.3%높음8.7
CVE-2026-95820A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f…0.3%낮음2.1
CVE-2026-12215The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute…0.3%보통5.3
CVE-2026-102143An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance…0.3%높음7.5
CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField an…0.3%높음7.6
CVE-2026-92247A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the functio…0.3%낮음2.0
CVE-2026-96515This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input valida…0.3%높음8.6
CVE-2026-85208A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element …0.3%보통5.5
CVE-2026-64949Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitra…0.3%높음8.6
CVE-2026-5695Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authentica…0.3%높음8.4
CVE-2026-91849A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of th…0.3%낮음2.1
CVE-2026-104637A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699df…0.3%보통5.5
CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor va…0.3%높음7.2
CVE-2026-56590HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file va…0.3%보통6.4
CVE-2026-96513A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing …0.3%보통5.5
CVE-2026-102842A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a…0.3%낮음2.1
CVE-2026-96431Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flow…0.3%심각9.3
CVE-2026-101071A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects u…0.3%낮음2.1
CVE-2026-85134Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus …0.3%높음8.8
CVE-2026-102137An authenticated administrator could bypass the content validation applied to an administrative file upload an…0.3%보통4.1
CVE-2026-88745EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.0.3%보통6.1
CVE-2026-64947A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker…0.3%높음7.5
CVE-2023-34854HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.0.2%보통6.6
CVE-2026-90857A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unk…0.2%낮음2.1
CVE-2026-91005A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function mov…0.2%낮음2.1
CVE-2026-90519A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown functio…0.2%낮음2.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.