CWE-693 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-693 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2024-21412Internet Shortcut Files Security Feature Bypass Vulnerability99.4%높음8.1● 랜섬웨어 캠페인에 사용됨CVE-2013-2465Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update…98.8%심각9.8● 실제 악용이 확인됨CVE-2019-1003030A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml…97.1%심각9.9● 랜섬웨어 캠페인에 사용됨CVE-2013-0431Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 throug…90.1%보통5.3● 실제 악용이 확인됨CVE-2025-40536SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that…73.6%심각9.8● 실제 악용이 확인됨CVE-2025-04117-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the…67.1%높음7.0● 실제 악용이 확인됨CVE-2024-29988SmartScreen Prompt Security Feature Bypass Vulnerability44.9%높음8.8● 실제 악용이 확인됨CVE-2026-21510Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f…24.2%높음8.8
전체 목록
92건
CVE-2026-21513악용 확인Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature …15.6%높음8.8
CVE-2026-32202악용 확인Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a netwo…4.9%보통4.3
CVE-2026-58704악용 확인In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to …0.6%높음8.8
CVE-2026-53710MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the…0.8%심각10.0
CVE-2026-92934vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revi…0.7%심각9.5
CVE-2026-93605vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist…0.7%심각10.0
CVE-2026-93606vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes …0.7%심각10.0
CVE-2026-81376Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a s…0.7%심각9.6
CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the …0.6%높음8.8
CVE-2026-92944vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototyp…0.6%심각9.3
CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform wit…0.6%높음8.8
CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a …0.6%높음8.8
CVE-2026-76825RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a …0.6%높음8.4
CVE-2026-101900Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig read…0.5%보통6.9
CVE-2026-76059IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass t…0.5%높음8.8
CVE-2026-92948vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox e…0.4%심각9.4
CVE-2026-92129Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts t…0.4%높음7.5
CVE-2026-91949FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthen…0.4%심각9.2
CVE-2026-57133PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisona…0.4%높음8.8
CVE-2026-39353InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1…0.4%심각9.1
CVE-2026-92938vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when tha…0.4%심각9.4
CVE-2026-92956vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when r…0.4%심각10.0
CVE-2026-57138PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builti…0.4%심각9.9
CVE-2026-57136PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/…0.4%높음8.8
CVE-2026-100676January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly re…0.4%높음8.8
CVE-2026-77401Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allo…0.4%보통6.8
CVE-2026-79919MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code runnin…0.4%보통6.3
CVE-2026-45770Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%높음7.5
CVE-2026-57137PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/…0.4%높음8.8
CVE-2026-47424Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter pe…0.4%높음7.5
CVE-2026-79918MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD …0.4%보통6.3
CVE-2026-92121In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an intern…0.3%높음7.5
CVE-2026-78552The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configura…0.3%보통6.0
CVE-2026-92778CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing…0.3%보통5.3
CVE-2026-86800The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check reque…0.3%보통5.3
CVE-2026-86796The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce re…0.3%보통5.3
CVE-2026-87808SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7). The prior fix (co…0.3%높음8.7
CVE-2026-57120PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits ru…0.3%보통6.5
CVE-2026-77892No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a phy…0.3%보통6.8
CVE-2026-57135PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/…0.3%높음7.6
CVE-2026-54694SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combin…0.3%심각9.6
CVE-2026-92959vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.pro…0.3%높음7.1
CVE-2026-102674Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.3%높음8.2
CVE-2026-90957Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit e…0.2%보통5.1
CVE-2026-20331As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec…0.2%심각9.6
CVE-2026-86894A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be a…0.2%높음7.5
CVE-2026-79638Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통5.3
CVE-2026-55366In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This c…0.2%심각9.8
CVE-2026-90950The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registrat…0.2%보통5.3
CVE-2026-79298An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a loc…0.2%높음8.4
CVE-2026-94251A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape …0.2%보통6.5
CVE-2026-92962vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSand…0.2%낮음2.1
CVE-2025-71424Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to a…0.2%보통5.1
CVE-2026-54577mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-a…0.2%낮음2.0
CVE-2026-57012In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could …0.2%높음8.4
CVE-2026-102673Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior …0.1%높음8.2
CVE-2026-56979In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead…0.1%보통6.7
CVE-2026-56881In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This cou…0.1%높음8.4
CVE-2026-55359In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead…0.1%높음7.8
CVE-2026-55302In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead…0.1%보통6.7
CVE-2026-0189In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This coul…0.1%높음8.4
CVE-2026-58678In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to loca…0.1%높음7.8
CVE-2026-85288Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortc…0.1%보통6.7
CVE-2026-56982In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local esca…0.1%높음7.8
CVE-2026-56970In multiple locations, there is a possible permission bypass due to a missing permission check. This could lea…0.1%높음8.4
CVE-2026-56941In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. T…0.1%높음8.4
CVE-2026-56973In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This coul…0.1%보통6.7
CVE-2026-55304In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the …0.1%보통6.7
CVE-2026-0187In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic erro…0.1%보통6.7
CVE-2026-0186In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. …0.1%보통6.7
CVE-2026-91796The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allo…0.1%보통6.1
CVE-2026-105083ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silen…0.1%낮음1.8
CVE-2026-0306A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Ag…0.1%보통5.8
CVE-2026-58767In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in th…0.1%보통6.7
CVE-2026-28664In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. …0.1%높음7.8
CVE-2026-58726In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could…0.1%보통6.7
CVE-2026-58755In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error …0.1%보통6.7
CVE-2026-58747In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. T…0.1%보통6.7
CVE-2026-58765In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escal…0.1%보통6.7
CVE-2026-57006In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local info…0.1%보통4.4
CVE-2026-58766In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in th…0.1%높음7.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.