$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-674 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-674

전체 목록

54건

CVE-2026-54451Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that dec…0.5%높음8.2
CVE-2026-91765cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthen…0.5%높음7.5
CVE-2026-53752docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX…0.4%높음7.5
CVE-2026-95861A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in ce…0.5%높음7.5
CVE-2026-104020Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticat…0.4%높음8.7
CVE-2026-19248QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untru…0.4%높음7.1
CVE-2026-83663Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a …0.4%높음8.7
CVE-2026-96288Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Er…0.4%높음8.2
CVE-2026-96289Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0…0.4%높음8.2
CVE-2026-94650Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: befor…0.4%높음8.2
CVE-2026-85493Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thr…0.4%높음8.7
CVE-2026-12358IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient vali…0.4%높음7.5
CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursio…0.4%높음8.7
CVE-2026-73321XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authen…0.4%높음7.1
CVE-2026-59156OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant …0.4%보통6.5
CVE-2026-89418google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can se…0.4%높음8.7
CVE-2026-91968vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that acc…0.4%높음7.1
CVE-2026-102281Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a sing…0.4%높음7.5
CVE-2026-77465toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 genera…0.4%높음7.5
CVE-2026-61811Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud wo…0.4%보통6.5
CVE-2026-102496Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so …0.4%높음7.5
CVE-2026-102495Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can…0.4%높음7.5
CVE-2026-102497The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, …0.4%높음7.5
CVE-2026-63386js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in …0.4%보통5.3
CVE-2026-95844Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names …0.4%높음8.7
CVE-2026-84851An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthe…0.3%높음8.7
CVE-2026-102276The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19…0.4%높음7.5
CVE-2026-102278The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20…0.4%높음7.5
CVE-2026-90472msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recu…0.3%보통6.9
CVE-2026-11573Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the a…0.3%높음7.1
CVE-2026-102510Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excess…0.3%높음8.7
CVE-2026-103087Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3…0.3%높음7.1
CVE-2026-103600Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle …0.3%높음8.7
CVE-2026-19201An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions…0.3%보통6.6
CVE-2026-103118A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function Ex…0.3%보통5.3
CVE-2026-102265PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api…0.3%보통5.3
CVE-2026-68914Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON d…0.3%높음8.7
CVE-2026-22591eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object M…0.3%높음7.5
CVE-2026-88763A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide sec…0.3%보통5.9
CVE-2026-66858The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a …0.3%높음8.7
CVE-2026-78253Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denia…0.3%낮음2.3
CVE-2026-100702Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, an…0.3%높음8.2
CVE-2026-92564A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to…0.2%미평가
CVE-2026-75655Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in…0.2%높음7.8
CVE-2026-59168Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0…0.1%보통6.2
CVE-2026-17440IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.1%보통5.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.