CWE-732 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-732 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2019-15752Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a T…48.6%높음7.8● 랜섬웨어 캠페인에 사용됨CVE-2018-13374A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.…37.8%보통4.3● 실제 악용이 확인됨CVE-2022-22960VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation…35.5%높음7.8● 실제 악용이 확인됨CVE-2021-23874Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a…1.0%높음7.8CVE-2026-85887Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker …0.9%높음7.7CVE-2026-19583Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the…0.6%심각9.9CVE-2026-39353InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …0.4%심각9.1CVE-2026-77256MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…0.4%높음8.3
전체 목록
41건
CVE-2026-76104Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource…0.4%보통5.5
CVE-2026-13673An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Man…0.4%높음8.8
CVE-2026-92941vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers t…0.3%심각10.0
CVE-2026-94204The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permission…0.3%높음8.7
CVE-2026-87988An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions thr…0.3%심각10.0
CVE-2026-89282The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory…0.3%심각9.1
CVE-2026-95627When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution…0.2%높음7.7
CVE-2026-95667The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/lo…0.2%보통6.9
CVE-2026-79617Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Re…0.1%높음7.1
CVE-2026-80054Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.5
CVE-2026-104854Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creat…0.1%높음8.5
CVE-2026-45726Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, impo…0.1%높음7.6
CVE-2026-68490Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to…0.1%높음8.2
CVE-2026-49811Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critic…0.1%높음8.4
CVE-2026-89281The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vul…0.1%높음8.4
CVE-2026-47518NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component…0.1%보통6.0
CVE-2021-43613An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are expo…0.1%보통6.5
CVE-2026-77268MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.1%보통5.5
CVE-2026-54447garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. P…0.1%높음8.4
CVE-2026-84828A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' g…0.1%보통6.5
CVE-2024-58383Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode…0.1%높음8.4
CVE-2026-80112PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.…0.1%높음8.5
CVE-2026-57843NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivile…0.1%보통6.8
CVE-2026-82312OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause…0.1%낮음1.8
CVE-2026-48722Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextfl…0.1%보통5.5
CVE-2026-76159Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows ver…0.1%높음7.0
CVE-2026-91798A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an in…0.1%높음8.8
CVE-2026-91800A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insuff…0.1%높음8.8
CVE-2026-84414IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary f…0.1%높음7.8
CVE-2026-82164Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critic…0.1%높음7.1
CVE-2026-15952Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager …0.1%높음7.1
CVE-2026-73598Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permissi…0.1%높음7.8
CVE-2026-105165A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process…보통5.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.