CWE-552 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-552 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2020-17519A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attack…97.8%높음7.5● 실제 악용이 확인됨CVE-2025-11371In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unaut…92.1%높음7.5● 실제 악용이 확인됨CVE-2016-3715The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to…75.3%보통5.5● 실제 악용이 확인됨CVE-2017-16651Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized acce…45.7%높음7.8● 실제 악용이 확인됨CVE-2025-48928The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content i…0.6%보통4.0CVE-2026-54629Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file…1.0%높음7.5CVE-2026-71379The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by …0.4%심각10.0CVE-2026-75164An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway fi…0.4%보통6.5
전체 목록
18건
CVE-2026-77259MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.4%높음7.7
CVE-2026-77884Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local ne…0.3%높음7.1
CVE-2026-67402An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the…0.3%심각9.2
CVE-2026-80494The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it…0.3%높음8.6
CVE-2026-68831Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized …0.3%보통5.5
CVE-2026-58415Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Se…0.3%보통5.3
CVE-2026-74853The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, …0.2%보통6.8
CVE-2026-85175SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() functio…0.2%높음8.7
CVE-2026-15915IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive …0.1%보통6.2
CVE-2026-6544IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead…0.1%보통6.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.