$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-73 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-73

전체 목록

86건

CVE-2026-90817An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Im…1.0%심각9.8
CVE-2026-69355External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute co…0.8%높음8.8
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticat…0.8%심각9.1
CVE-2026-85684marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails …0.7%높음8.8
CVE-2026-16338IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perfo…0.6%심각9.9
CVE-2026-65125NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external con…0.6%보통6.6
CVE-2026-54675FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the…0.6%높음8.7
CVE-2026-90946DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/…0.6%높음8.7
CVE-2026-66302External control of file name or path in Skype for Business allows an unauthorized attacker to execute code ov…0.5%심각9.8
CVE-2026-54582mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for in…0.5%보통6.0
CVE-2026-53940Conda is a system-level binary package and environment manager that runs on major operating systems and platfo…0.5%높음8.8
CVE-2026-15983The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Dele…0.5%높음8.1
CVE-2026-54583mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, …0.5%높음8.3
CVE-2026-69805External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a net…0.5%높음7.5
CVE-2026-6205An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) bef…0.5%높음8.1
CVE-2026-73171Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-re…0.5%높음8.6
CVE-2026-100638SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allo…0.5%높음8.3
CVE-2026-100637SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows …0.5%높음8.3
CVE-2026-90932LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup h…0.5%높음8.6
CVE-2026-54584mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, i…0.5%보통5.3
CVE-2026-85668Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability …0.4%높음8.7
CVE-2026-88899knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/op…0.4%심각9.3
CVE-2026-77247MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.4%높음8.3
CVE-2026-75602OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download featu…0.4%보통6.5
CVE-2026-76553The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supp…0.4%보통6.5
CVE-2026-13248An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface …0.4%높음8.8
CVE-2026-103591DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET …0.4%높음8.7
CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated atta…0.4%심각9.3
CVE-2026-85603Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that …0.4%높음7.1
CVE-2026-94401MISP has a file-handling vulnerability that could let certain authenticated users make the server read files o…0.4%높음8.3
CVE-2026-101126Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submissi…0.4%보통6.9
CVE-2026-85176DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and …0.3%높음8.7
CVE-2026-83603Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-…0.3%높음8.4
CVE-2026-73496MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.3%높음7.7
CVE-2026-53581OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and versio…0.3%심각9.0
CVE-2026-62804External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code…0.3%높음7.8
CVE-2026-96656Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on lo…0.3%높음8.6
CVE-2026-102146An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could writ…0.3%보통6.5
CVE-2026-61647NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generate…0.3%높음7.1
CVE-2026-77005The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before d…0.3%심각9.6
CVE-2026-101148The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integratio…0.3%심각10.0
CVE-2026-85687surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /pa…0.3%높음8.7
CVE-2026-86995n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node valida…0.3%보통5.3
CVE-2026-103255n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal…0.3%높음7.1
CVE-2026-87815SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint …0.3%높음8.4
CVE-2026-103398OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request …0.3%높음8.6
CVE-2026-79692Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.3%높음7.3
CVE-2026-92164Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.…0.3%보통6.5
CVE-2026-78620The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payload…0.3%보통5.9
CVE-2026-86751Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated …0.2%높음8.4
CVE-2026-69383External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges loc…0.2%높음7.0
CVE-2026-53956Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior…0.2%보통5.4
CVE-2026-76796The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file p…0.2%보통5.1
CVE-2026-86741Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout c…0.2%높음8.4
CVE-2026-81347The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllabl…0.2%보통5.9
CVE-2026-19253The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem…0.2%높음8.7
CVE-2026-50158yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download…0.2%높음7.7
CVE-2026-19860The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restric…0.2%보통5.5
CVE-2026-85160AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stop…0.2%높음7.2
CVE-2026-91797Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting…0.2%높음7.8
CVE-2026-82194The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied pa…0.2%보통5.5
CVE-2026-92595Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `dis…0.2%보통6.0
CVE-2026-77006The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not chec…0.2%심각9.6
CVE-2026-55062uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in …0.2%높음8.4
CVE-2026-63225Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.…0.2%보통4.4
CVE-2026-104853Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx mig…0.2%보통5.8
CVE-2026-91072The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routi…0.2%보통4.4
CVE-2026-49836psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObjec…0.2%보통4.6
CVE-2026-93987rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volu…0.2%보통4.6
CVE-2026-97662An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 m…0.1%보통6.9
CVE-2026-80119PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.…0.1%높음8.5
CVE-2026-71453- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attac…0.1%보통5.6
CVE-2026-10739Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM p…0.1%높음8.5
CVE-2026-80118PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.…0.1%높음8.4
CVE-2026-81830The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the…0.1%보통5.6
CVE-2026-102141Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker …0.1%보통6.7
CVE-2026-10726Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privi…0.1%보통6.8
CVE-2020-9752Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem a…심각9.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.