CWE-59 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-59 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2022-30333RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an ex…99.2%높음7.5● 실제 악용이 확인됨CVE-2020-36193Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadeq…70.6%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2024-57728SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files an…64.7%높음7.2● 실제 악용이 확인됨CVE-2023-36874Windows Error Reporting Service Elevation of Privilege Vulnerability42.6%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2020-0787An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv…42.5%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2019-0841An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improp…41.4%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2022-21999Windows Print Spooler Elevation of Privilege Vulnerability41.0%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2021-41379Windows Installer Elevation of Privilege Vulnerability19.5%보통5.5
전체 목록
88건
CVE-2019-1253랜섬웨어 악용An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junc…11.6%높음7.8
CVE-2015-1130악용 확인The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentica…9.9%높음7.8
CVE-2020-0683악용 확인An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic lin…7.6%높음7.8
CVE-2019-1064랜섬웨어 악용An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handl…6.9%높음7.8
CVE-2019-1069랜섬웨어 악용An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file op…6.1%높음7.8
CVE-2015-5287악용 확인The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with ce…5.0%높음7.8
CVE-2025-60710랜섬웨어 악용Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an aut…4.6%높음7.8
CVE-2025-48384악용 확인Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides …4.2%높음8.0
CVE-2019-1385랜섬웨어 악용An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs…3.6%높음7.8
CVE-2019-1315랜섬웨어 악용An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard li…3.5%높음7.8
CVE-2020-0638랜섬웨어 악용An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exp…2.4%높음7.8
CVE-2019-1129랜섬웨어 악용An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handl…1.8%높음7.8
CVE-2019-1130랜섬웨어 악용An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handl…1.7%높음7.8
CVE-2026-41091악용 확인Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized atta…0.4%높음7.8
CVE-2026-81963악용 확인Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized at…0.4%높음7.8
CVE-2026-70563Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacke…0.9%높음8.1
CVE-2026-101894The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input…0.8%심각9.1
CVE-2026-67368Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to …0.7%높음8.8
CVE-2026-85731oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layer…0.7%높음8.8
CVE-2026-15815Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A cr…0.7%높음8.8
CVE-2026-96279A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs …0.6%보통6.5
CVE-2026-103263Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links …0.5%높음8.2
CVE-2026-85583SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoi…0.5%높음7.1
CVE-2026-86861pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the req…0.5%보통6.0
CVE-2026-59944Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a ma…0.5%보통6.1
CVE-2026-87910When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from…0.4%보통5.7
CVE-2026-55074Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through ve…0.4%높음8.2
CVE-2026-90930File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links with…0.4%높음7.6
CVE-2026-82331Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apa…0.4%심각9.8
CVE-2026-100692Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement ch…0.4%높음8.7
CVE-2026-94620Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior…0.4%심각9.4
CVE-2026-87799Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.1…0.4%심각9.9
CVE-2026-100715Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion…0.4%높음8.5
CVE-2026-100716Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) …0.4%심각9.4
CVE-2026-55828qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine …0.4%보통6.0
CVE-2026-69289Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an author…0.4%높음7.8
CVE-2026-102242Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for …0.4%높음8.6
CVE-2026-100690Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under …0.3%높음8.7
CVE-2026-68491An insufficient check allowed for the overwrite of arbitrary files via a symlink.0.3%심각9.4
CVE-2026-69771Improper link resolution before file access ('link following') in Windows Container Manager Service allows an …0.3%보통4.7
CVE-2026-89258Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directorie…0.3%심각9.3
CVE-2026-96282A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at a…0.3%낮음3.1
CVE-2026-93353copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated S…0.3%보통6.0
CVE-2026-90807A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFi…0.3%낮음2.1
CVE-2026-68830Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Devic…0.3%보통5.5
CVE-2026-69425Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker t…0.3%보통4.7
CVE-2026-69379Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker t…0.3%높음7.0
CVE-2026-89021MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image…0.2%보통6.9
CVE-2026-100838Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policie…0.2%높음8.6
CVE-2026-83999Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Dedupli…0.2%높음7.0
CVE-2026-88016rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.2%높음7.1
CVE-2026-79534mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolutio…0.2%보통5.9
CVE-2026-82049In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted ar…0.2%높음8.4
CVE-2026-87798Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.…0.2%보통5.8
CVE-2026-12345The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the t…0.2%보통5.9
CVE-2026-92253Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.6…0.2%보통5.2
CVE-2026-77179On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unl…0.2%심각9.4
CVE-2026-85092LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when openin…0.2%보통5.2
CVE-2026-80430Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in k…0.2%보통4.6
CVE-2026-87766A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can fol…0.1%높음8.8
CVE-2026-100419gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechani…0.1%높음7.3
CVE-2026-96284A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository …0.1%낮음2.5
CVE-2026-79699A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout head…0.1%보통4.4
CVE-2026-71182Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Ac…0.1%낮음3.0
CVE-2026-71181Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Ac…0.1%낮음3.0
CVE-2026-102118A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell …0.1%높음7.8
CVE-2026-88265A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a ho…0.1%보통5.6
CVE-2026-102113A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execut…0.1%높음7.8
CVE-2026-88264A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setu…0.1%보통5.6
CVE-2026-86424ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the v…0.1%낮음2.0
CVE-2026-10739Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM p…0.1%높음8.5
CVE-2026-86469A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating t…0.1%보통5.3
CVE-2026-81310Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux …0.1%보통5.2
CVE-2026-86422ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on W…0.1%낮음1.0
CVE-2026-92371TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerabili…0.1%높음7.0
CVE-2026-54587mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_O…0.1%보통5.8
CVE-2026-54576mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_…0.1%보통5.8
CVE-2026-78622The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem juncti…0.1%보통6.0
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.