CWE-639 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-639 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2026-55255Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an In…0.9%높음8.4CVE-2026-100885A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the…1.0%보통5.5CVE-2026-86465Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed wi…0.8%보통6.5CVE-2026-69865Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthori…0.8%심각10.0CVE-2026-75517Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu inte…0.7%보통6.5CVE-2026-86678ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user t…0.7%높음8.8CVE-2026-69375Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized a…0.6%보통6.5CVE-2026-84791ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to…0.6%높음7.1
전체 목록
120건
CVE-2026-84789ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken …0.6%높음7.1
CVE-2026-83711Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorize…0.6%심각10.0
CVE-2026-20342A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, rem…0.5%높음7.7
CVE-2026-54671WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty res…0.6%높음8.8
CVE-2026-53639Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18…0.5%보통6.3
CVE-2026-92469zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center…0.5%높음7.2
CVE-2026-78462Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypa…0.5%높음8.8
CVE-2026-47156MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass i…0.5%심각9.3
CVE-2026-61744InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacke…0.5%보통6.5
CVE-2026-63506Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAu…0.5%높음8.8
CVE-2026-84860ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endp…0.5%높음8.8
CVE-2026-82685Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an aut…0.5%높음7.6
CVE-2026-63647CordysCRM is an open source AI-powered customer relationship management system that supports private deploymen…0.5%심각9.3
CVE-2026-95655Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authent…0.5%높음8.6
CVE-2026-48975HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and Ma…0.5%높음8.1
CVE-2026-48826HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/h…0.5%높음8.1
CVE-2026-94534lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpo…0.5%높음7.1
CVE-2026-77426Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five aut…0.5%높음7.1
CVE-2026-85607Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, …0.5%높음8.7
CVE-2026-94535lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that a…0.5%높음7.1
CVE-2026-81505Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/…0.5%높음7.1
CVE-2026-89333The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Obj…0.5%보통6.5
CVE-2026-55625GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /…0.5%보통4.9
CVE-2026-88877Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingres…0.4%심각9.3
CVE-2026-94497jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multi…0.5%높음8.7
CVE-2026-75101An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticate…0.4%보통6.0
CVE-2026-48976HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/int…0.4%높음8.1
CVE-2026-82441Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifa…0.4%심각9.1
CVE-2026-79409An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart …0.4%보통6.5
CVE-2026-69857Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform s…0.4%높음8.5
CVE-2026-79758Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. …0.4%보통5.4
CVE-2026-94532lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that …0.4%높음7.1
CVE-2026-94533lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows a…0.4%높음7.1
CVE-2026-93991Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkf…0.4%높음8.3
CVE-2026-93660SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allo…0.4%높음7.1
CVE-2026-86263A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impac…0.4%보통5.5
CVE-2026-86262A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384…0.4%보통5.5
CVE-2026-86261A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impa…0.4%보통5.5
CVE-2026-69190Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update…0.4%보통6.3
CVE-2026-61748InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print…0.4%보통4.3
CVE-2026-92714The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to,…0.4%보통6.5
CVE-2026-89063The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure D…0.4%높음7.5
CVE-2026-93955A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is t…0.4%낮음2.1
CVE-2026-90521A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70…0.4%낮음2.1
CVE-2026-74864sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" …0.4%심각9.3
CVE-2026-85624Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure th…0.4%높음7.1
CVE-2026-76901CordysCRM is an open source AI-powered customer relationship management system that supports private deploymen…0.4%보통5.8
CVE-2026-62279LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6…0.4%높음7.1
CVE-2026-54529SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmi…0.4%보통5.3
CVE-2026-88065`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules.…0.4%높음7.5
CVE-2026-47094SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated at…0.4%높음8.7
CVE-2026-91144ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the downl…0.4%높음8.7
CVE-2026-81915Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. Th…0.4%보통5.1
CVE-2026-55178GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. P…0.4%높음7.5
CVE-2026-95683In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. …0.4%보통5.3
CVE-2026-85105A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait…0.4%보통6.9
CVE-2026-92468zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-cent…0.4%높음7.1
CVE-2026-93736Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authent…0.4%보통5.3
CVE-2026-74865sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be b…0.4%심각9.2
CVE-2026-77293TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/fil…0.4%높음7.1
CVE-2026-54178backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…0.4%높음8.1
CVE-2026-87739An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigg…0.4%보통6.9
CVE-2026-97636Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with…0.4%보통6.5
CVE-2026-94152A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an u…0.4%낮음2.1
CVE-2026-94393When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID wit…0.4%보통6.4
CVE-2026-94374MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the …0.4%높음8.3
CVE-2026-93399The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu…0.4%심각9.1
CVE-2026-103233A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8f…0.4%낮음2.1
CVE-2026-82348Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with auth…0.4%높음7.7
CVE-2026-80254Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attac…0.4%높음7.1
CVE-2026-94494jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read ot…0.4%보통5.3
CVE-2026-103235MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation per…0.4%높음8.7
CVE-2026-92603ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete end…0.3%높음7.1
CVE-2026-19651IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to by…0.3%높음7.4
CVE-2026-93882The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to…0.4%높음7.5
CVE-2026-92567TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/da…0.3%높음7.1
CVE-2026-93758An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper ma…0.4%높음8.6
CVE-2026-90517A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown functi…0.3%보통5.5
CVE-2026-92765ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing au…0.3%높음7.1
CVE-2026-86183A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of th…0.3%보통5.5
CVE-2026-85381A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f6…0.3%보통5.5
CVE-2026-54180backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel pa…0.3%높음7.6
CVE-2026-91933Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allow…0.3%높음7.6
CVE-2026-77240WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-leve…0.3%심각9.9
CVE-2026-100177The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization che…0.3%보통6.3
CVE-2026-52743GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not valida…0.3%보통4.3
CVE-2026-94536lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint,…0.3%보통5.3
CVE-2026-61747InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/impor…0.3%보통4.3
CVE-2026-77385Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user wit…0.3%보통4.3
CVE-2026-79324Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr)…0.3%높음7.5
CVE-2026-100612Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_provid…0.3%높음8.6
CVE-2026-46498Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads calle…0.3%높음7.6
CVE-2026-77705The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user …0.3%높음7.2
CVE-2026-92716Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration en…0.3%높음8.6
CVE-2026-92605IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, task…0.3%높음7.1
CVE-2026-54050Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/…0.3%보통6.5
CVE-2026-92773Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before …0.3%높음7.1
CVE-2026-82125The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership…0.3%보통5.3
CVE-2026-56728Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vu…0.3%보통5.3
CVE-2026-90858A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a…0.3%보통5.5
CVE-2026-103446Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambd…0.3%높음7.4
CVE-2026-89262MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that perf…0.3%높음8.7
CVE-2026-90899Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store exte…0.3%높음8.2
CVE-2026-13471The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Inse…0.3%보통4.3
CVE-2026-100531The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file hand…0.3%높음7.1
CVE-2026-94405Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Em…0.3%보통5.3
CVE-2026-100679stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attacker…0.3%높음7.1
CVE-2026-100614Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that tru…0.3%높음8.7
CVE-2026-91109The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…0.3%보통6.5
CVE-2026-63205Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating …0.3%보통5.1
CVE-2026-54239Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the…0.3%높음8.8
CVE-2026-86277A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0…0.3%보통5.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.