CWE-497 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-497 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2021-31955Windows Kernel Information Disclosure Vulnerability81.1%보통5.5CVE-2026-69723Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows …1.0%보통5.7CVE-2026-71330Exposure of sensitive system information to an unauthorized control sphere in Windows Services for N…0.8%높음7.5CVE-2026-27553A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnost…0.5%보통6.5CVE-2026-69406Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows …0.5%보통5.5CVE-2026-69315Exposure of sensitive system information to an unauthorized control sphere in Windows License Manage…0.5%보통5.5CVE-2026-69339Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service M…0.5%보통5.5CVE-2026-81387Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel…0.4%보통5.5
전체 목록
22건
CVE-2026-81394Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an…0.4%보통5.5
CVE-2026-69832Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authori…0.4%보통5.6
CVE-2026-68842Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allo…0.4%보통5.5
CVE-2026-38058The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including t…0.3%높음8.6
CVE-2026-84712A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (Ap…0.3%보통5.3
CVE-2025-33141IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive info…0.3%보통6.5
CVE-2026-66840XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-…0.3%높음8.7
CVE-2026-97181GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers …0.3%보통6.9
CVE-2026-95600Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.0.3%보통5.3
CVE-2026-76968SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileg…0.2%보통6.5
CVE-2026-61911An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticat…0.2%보통4.3
CVE-2026-80119PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.…0.1%높음8.5
CVE-2026-80118PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.…0.1%높음8.4
CVE-2026-16006Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a lo…0.1%보통5.7
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.