CWE-640 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-640 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2023-7028An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 …94.6%심각9.8CVE-2026-93340Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows una…0.5%높음7.4CVE-2026-90522A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b…0.5%보통5.5CVE-2026-93453SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the a…0.5%높음8.7CVE-2026-101188A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects …0.5%보통5.5CVE-2026-86260A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef…0.4%보통5.5CVE-2026-53953GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…0.3%심각9.1CVE-2026-102115Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An u…0.3%심각9.8
전체 목록
12건
CVE-2026-14850The password reset funcionality is vulnerable to unauthorized account modification due to improper validation …0.3%높음8.8
CVE-2026-100870Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links u…0.3%높음8.7
CVE-2026-6285Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc…0.3%높음7.5
CVE-2026-81905Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, p…0.2%보통6.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.