$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-522 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-522

CWE-522 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

전체 목록

66건

CVE-2026-69805External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a net…0.5%높음7.5
CVE-2026-54618Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an…0.5%심각9.4
CVE-2026-82434Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.…0.5%심각10.0
CVE-2026-64918Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing o…0.5%보통6.5
CVE-2026-76854Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_us…0.5%높음7.1
CVE-2026-48976HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/int…0.4%높음8.1
CVE-2026-82433Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-lev…0.4%보통6.5
CVE-2026-84179Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration a…0.4%보통6.5
CVE-2026-55870GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators…0.4%낮음2.3
CVE-2026-81861CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication in…0.4%보통5.9
CVE-2026-61516Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows un…0.4%심각9.3
CVE-2026-75015Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configure…0.4%보통4.9
CVE-2026-20234As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services E…0.4%심각9.9
CVE-2026-104051PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers …0.4%높음8.8
CVE-2026-89064The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protectio…0.3%보통5.3
CVE-2026-76859Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_…0.3%높음7.1
CVE-2026-76857Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the d…0.3%높음7.1
CVE-2026-92759SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSeria…0.3%높음7.1
CVE-2026-85717The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously …0.3%보통6.8
CVE-2026-92882Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk…0.4%보통5.3
CVE-2026-91766When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Pro…0.3%보통5.9
CVE-2026-94611authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serial…0.3%높음8.1
CVE-2026-86600In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and a…0.3%높음8.2
CVE-2026-92537The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Prote…0.3%보통5.3
CVE-2026-76969@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP …0.3%심각9.4
CVE-2026-85700Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any…0.3%높음7.1
CVE-2026-92256NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.…0.3%높음7.1
CVE-2026-76871Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote…0.3%높음7.1
CVE-2026-91982Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/u…0.3%보통5.3
CVE-2026-100298In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device…0.3%높음8.7
CVE-2026-86175NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API respons…0.3%높음7.1
CVE-2026-86726AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows a…0.3%높음7.1
CVE-2026-85720The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously …0.3%보통5.9
CVE-2026-82070A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitori…0.2%높음7.1
CVE-2026-8862IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application so…0.2%높음7.5
CVE-2026-92133Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative Git…0.2%보통5.4
CVE-2026-100264In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the se…0.2%낮음2.7
CVE-2026-81208IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information …0.2%높음7.7
CVE-2026-85719The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously …0.2%높음7.5
CVE-2026-81930Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before int…0.2%보통6.3
CVE-2026-86862pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of…0.2%높음7.1
CVE-2026-53603nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session…0.2%높음7.1
CVE-2026-103256n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and …0.2%높음7.1
CVE-2026-93474Charging station authentication identifiers are publicly accessible via web-based mapping platforms.0.2%보통6.9
CVE-2026-82786Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If t…0.2%높음8.2
CVE-2026-88013rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.2%낮음3.7
CVE-2026-63207Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated admin…0.2%보통6.9
CVE-2026-49449Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From…0.2%낮음2.5
CVE-2026-92680Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote server…0.2%보통6.8
CVE-2026-90895Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web a…0.2%높음8.4
CVE-2026-101089Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that r…0.2%낮음2.3
CVE-2026-11921IBM Verify Identity Access containers may not apply management password change operations correctly.0.1%미평가
CVE-2026-45726Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, impo…0.1%높음7.6
CVE-2026-100569OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment…0.1%보통6.8
CVE-2026-17643IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive …0.1%높음8.8
CVE-2026-18124IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive …0.1%보통6.5
CVE-2018-12038An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encr…보통4.2
CVE-2018-17969Samsung SCX-6545X V2.00.03.01 03-23-2012 devices allows remote attackers to discover cleartext credentials via…심각9.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.