CWE-436 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-436 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2026-63030WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route c…10.1%심각9.8● 실제 악용이 확인됨CVE-2025-48384Git is a fast, scalable, distributed revision control system with an unusually rich command set that…4.2%높음8.0CVE-2026-73511Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…0.6%보통5.3CVE-2026-73553Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36…0.5%높음7.5CVE-2026-93750http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() f…0.4%높음8.2CVE-2026-85184@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by m…0.3%심각9.1CVE-2026-81378Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security f…0.3%높음8.2CVE-2026-82537Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execu…0.3%높음7.7
전체 목록
15건
CVE-2026-88004Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint de…0.3%높음7.0
CVE-2026-92598Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing …0.3%높음8.3
CVE-2026-92597Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser…0.3%높음8.3
CVE-2026-84394fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error.…0.2%높음7.5
CVE-2026-87627Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote att…0.2%미평가
CVE-2026-86818fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto sc…0.2%보통4.8
CVE-2026-91835A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFi…0.1%낮음0.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.