CWE-470 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-470 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2021-21985The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input valid…100.0%심각9.8● 실제 악용이 확인됨CVE-2026-82078An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCu…61.4%심각9.4CVE-2026-58400GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.…1.2%심각9.1CVE-2026-86792Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found …1.2%높음8.8CVE-2026-55107Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing exe…0.8%심각10.0CVE-2026-41871Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflect…0.8%심각9.8CVE-2026-78030DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att…0.7%심각9.8CVE-2026-41870Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control o…0.7%높음8.8
전체 목록
24건
CVE-2026-62379Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /aut…0.7%심각9.8
CVE-2026-70410Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Cal…0.6%높음8.8
CVE-2026-76825RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a …0.6%높음8.4
CVE-2026-93762Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application t…0.6%심각9.2
CVE-2026-93765Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mappin…0.5%높음8.3
CVE-2026-102094Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not suffic…0.5%높음7.2
CVE-2026-101292Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMe…0.4%높음8.2
CVE-2026-61599djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance.…0.4%높음8.8
CVE-2026-66269Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Inpu…0.4%높음7.3
CVE-2026-79987A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute …0.4%높음8.7
CVE-2026-10853IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially e…0.4%높음7.5
CVE-2026-96740A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the …0.4%보통6.5
CVE-2026-102580A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name t…0.2%보통4.3
CVE-2026-96672Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula val…0.2%보통5.3
CVE-2026-18123IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial o…0.2%높음7.6
CVE-2026-100308Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow c…0.1%높음8.4
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.