CWE-636 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-636 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-77560Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded …0.6%높음8.1CVE-2026-95676A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync firs…0.5%높음7.4CVE-2026-77866Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a v…0.5%심각9.0CVE-2026-53459Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in…0.4%심각9.3CVE-2026-95848Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or auth…0.4%심각9.3CVE-2026-61595djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…0.4%높음7.7CVE-2026-100304TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermissio…0.4%보통6.0CVE-2026-81379Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypas…0.3%높음8.2
전체 목록
14건
CVE-2026-61788DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22…0.3%높음7.4
CVE-2026-92591Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, w…0.2%높음8.2
CVE-2026-88831BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask…0.2%보통5.3
CVE-2026-86120APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that f…0.2%보통5.3
CVE-2026-85649(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerabilit…0.2%높음7.9
CVE-2026-100860heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow no…0.1%보통6.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.