$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-502 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-502

CWE-502 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

10.0APCWE-20● 랜섬웨어 캠페인에 사용됨CVE-2021-44228Apache · Log4j2Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI …100.0%심각10.07.2FOCWE-502● 랜섬웨어 캠페인에 사용됨CVE-2023-0669Fortra · GoAnywhere MFTFortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vu…100.0%높음7.29.8FOCWE-502● 랜섬웨어 캠페인에 사용됨CVE-2021-35464ForgeRock · Access Management (AM)ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession para…100.0%심각9.89.8MICWE-502● 랜섬웨어 캠페인에 사용됨CVE-2025-53770Microsoft · SharePointDeserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized …100.0%심각9.89.8ADCWE-502● 랜섬웨어 캠페인에 사용됨CVE-2023-29300Adobe · ColdFusionAdobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earli…100.0%심각9.89.8MICWE-502● 실제 악용이 확인됨CVE-2025-59287Microsoft · WindowsDeserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker t…100.0%심각9.88.0MICWE-502● 랜섬웨어 캠페인에 사용됨CVE-2022-41082Microsoft · Exchange ServerMicrosoft Exchange Server Remote Code Execution Vulnerability100.0%높음8.09.8IBCWE-502● 랜섬웨어 캠페인에 사용됨CVE-2022-47986IBM · Aspera FaspexIBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary…100.0%심각9.8

전체 목록

120건

CVE-2018-2628악용 확인Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Comp…100.0%심각9.8
CVE-2020-10189악용 확인Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of u…99.9%심각9.8
CVE-2025-24813악용 확인Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure an…99.9%심각9.8
CVE-2022-35405악용 확인Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated r…99.9%심각9.8
CVE-2023-46604랜섬웨어 악용The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a r…99.9%심각9.8
CVE-2023-21839악용 확인Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported v…99.9%높음7.5
CVE-2020-7961악용 확인Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute a…99.9%심각9.8
CVE-2025-55182랜섬웨어 악용A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19…99.8%심각10.0
CVE-2025-10035랜섬웨어 악용A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a valid…99.8%심각9.8
CVE-2019-18935랜섬웨어 악용Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the …99.7%심각9.8
CVE-2017-1000353악용 확인Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remot…99.7%심각9.8
CVE-2017-9805악용 확인The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHand…99.4%높음8.1
CVE-2020-0618랜섬웨어 악용A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly ha…99.0%높음8.8
CVE-2025-49113악용 확인Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users be…98.9%높음8.8
CVE-2018-1000861악용 확인A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.13…98.3%심각9.8
CVE-2021-39144악용 확인XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerabilit…98.1%높음8.5
CVE-2015-7450악용 확인Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and m…97.8%심각9.8
CVE-2021-42237랜섬웨어 악용Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attac…97.6%심각9.8
CVE-2020-2555악용 확인Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invoc…97.1%심각9.8
CVE-2023-38203랜섬웨어 악용Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by…97.1%심각9.8
CVE-2025-5086악용 확인A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 20…96.9%심각9.0
CVE-2015-4852악용 확인The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote …96.0%심각9.8
CVE-2021-26857랜섬웨어 악용Microsoft Exchange Server Remote Code Execution Vulnerability95.8%높음7.8
CVE-2019-10068악용 확인An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.…95.1%심각9.8
CVE-2025-24016악용 확인Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in vers…93.8%심각9.9
CVE-2019-6340악용 확인Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal …92.0%높음8.1
CVE-2017-12149랜섬웨어 악용In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the…90.7%심각9.8
CVE-2017-3066악용 확인Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and e…90.6%심각9.8
CVE-2024-40711랜섬웨어 악용A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote…90.4%심각9.8
CVE-2023-40044랜섬웨어 악용In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deseria…90.4%높음8.8
CVE-2026-63077랜섬웨어 악용In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the ag…89.6%심각9.8
CVE-2025-26399랜섬웨어 악용SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote co…89.5%심각9.8
CVE-2024-28986악용 확인SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerabi…84.6%심각9.8
CVE-2025-40551악용 확인SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that c…84.2%심각9.8
CVE-2019-9874악용 확인Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0…83.7%심각9.8
CVE-2023-43208랜섬웨어 악용NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. …82.7%심각9.8
CVE-2021-23758악용 확인All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility o…82.6%심각9.8
CVE-2018-15133악용 확인In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of…76.8%높음8.1
CVE-2018-0824악용 확인A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle s…73.2%높음8.8
CVE-2020-5741악용 확인Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to e…72.9%높음7.2
CVE-2022-21445악용 확인Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (compo…62.5%심각9.8
CVE-2018-4939악용 확인Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitab…61.7%심각9.8
CVE-2023-21529랜섬웨어 악용Microsoft Exchange Server Remote Code Execution Vulnerability59.3%높음8.8
CVE-2025-53690악용 확인Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platf…51.1%심각9.0
CVE-2024-38094랜섬웨어 악용Microsoft SharePoint Remote Code Execution Vulnerability50.9%높음7.2
CVE-2026-12569랜섬웨어 악용A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPL…46.0%심각9.3
CVE-2026-20131랜섬웨어 악용A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Softwar…43.2%심각10.0
CVE-2020-17144악용 확인Microsoft Exchange Remote Code Execution Vulnerability36.5%높음8.4
CVE-2022-31199랜섬웨어 악용Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component aff…36.0%심각9.8
CVE-2025-0994악용 확인Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vul…31.1%높음8.6
CVE-2021-27852악용 확인Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticate…30.3%심각9.8
CVE-2026-20963악용 확인Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co…29.6%심각9.8
CVE-2025-23006랜섬웨어 악용Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Applianc…23.4%심각9.8
CVE-2018-0147악용 확인A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 …18.2%심각9.8
CVE-2023-26359악용 확인Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deser…17.0%심각9.8
CVE-2026-58644악용 확인Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co…15.9%심각9.8
CVE-2024-8069악용 확인Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if…14.6%보통5.1
CVE-2025-42999랜섬웨어 악용SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or m…13.9%심각9.1
CVE-2019-9875악용 확인Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated atta…13.8%높음8.8
CVE-2019-0344악용 확인Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7,…7.1%심각9.8
CVE-2019-15271악용 확인A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could …5.5%높음8.8
CVE-2024-20953악용 확인Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported versio…3.9%높음8.8
CVE-2021-31010악용 확인A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021…3.7%높음7.5
CVE-2025-3935악용 확인ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. AS…3.5%높음7.2
CVE-2026-50522악용 확인Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute co…3.0%심각9.8
CVE-2026-45659랜섬웨어 악용Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code…2.7%높음8.8
CVE-2026-45247악용 확인Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerabi…2.1%심각9.3
CVE-2025-8875악용 확인Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue …1.9%심각9.4
CVE-2026-12744A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote una…2.2%심각9.8
CVE-2026-12745A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote una…2.1%심각9.8
CVE-2026-69694Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacke…1.7%높음7.0
CVE-2026-28325SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vuln…1.5%높음8.8
CVE-2026-12651A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote aut…1.5%높음8.8
CVE-2026-12650A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote aut…1.5%심각9.9
CVE-2026-12648A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote aut…1.5%높음8.8
CVE-2026-77484Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.1.1%높음8.8
CVE-2026-81385Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute cod…1.0%높음8.8
CVE-2026-90919LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /…1.0%심각9.3
CVE-2026-43642Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the …1.0%심각9.2
CVE-2026-20307A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attack…1.0%심각9.9
CVE-2026-93467The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers…0.9%심각9.3
CVE-2026-65772Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over…0.9%높음8.8
CVE-2026-70416Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An un…0.9%심각10.0
CVE-2026-17086The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PH…0.9%높음8.8
CVE-2026-76834b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-…0.8%심각9.2
CVE-2026-81657IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on t…0.8%심각9.8
CVE-2026-47297Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network…0.8%높음8.1
CVE-2026-103040LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when star…0.8%심각9.3
CVE-2026-82384Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause de…0.8%심각9.8
CVE-2026-78006The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and…0.8%심각9.8
CVE-2026-46495OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy…0.7%심각9.2
CVE-2026-93088SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the d…0.7%심각9.8
CVE-2026-93872Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in t…0.7%높음7.7
CVE-2026-20340A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrar…0.7%높음8.8
CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers …0.7%심각9.3
CVE-2025-66455LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2…0.7%심각9.8
CVE-2026-11363The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Objec…0.7%보통6.6
CVE-2025-59953LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1…0.7%심각9.8
CVE-2026-65179NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacke…0.7%높음8.8
CVE-2026-54752NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox…0.7%심각9.6
CVE-2026-20242A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Softw…0.6%심각9.8
CVE-2026-96560LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started w…0.7%심각9.3
CVE-2023-54398Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.F…0.6%심각9.3
CVE-2026-10196The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vul…0.6%심각9.8
CVE-2026-103041LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deseria…0.6%심각9.3
CVE-2026-103395LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enable…0.6%심각9.3
CVE-2026-87719GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6…0.6%심각9.9
CVE-2026-91939Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction…0.6%심각9.3
CVE-2026-84832SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import …0.6%높음8.6
CVE-2026-83803Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with …0.6%높음7.7
CVE-2026-78175The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injectio…0.6%높음8.8
CVE-2026-55083DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. …0.6%심각9.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.