CWE-770 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-770 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2020-3566A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR So…3.7%높음8.6● 실제 악용이 확인됨CVE-2020-3569Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco …3.3%높음8.6CVE-2026-45769Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…1.2%높음7.5CVE-2026-69374Allocation of resources without limits or throttling in Windows SMB Server allows an authorized atta…1.1%보통6.5CVE-2026-93491A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vul…0.9%높음7.5CVE-2026-100274In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification templat…0.8%보통6.5CVE-2026-57099Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker…0.8%높음7.5CVE-2026-72978Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS)…0.8%보통5.9
전체 목록
120건
CVE-2026-50277dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming …0.8%높음7.5
CVE-2026-50276dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_…0.8%높음7.5
CVE-2026-50285Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.g…0.7%높음7.5
CVE-2026-93688SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validat…0.7%높음8.7
CVE-2026-93310A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component V…0.7%보통5.5
CVE-2026-93488A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated strea…0.7%높음7.5
CVE-2026-57227Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.7%높음7.5
CVE-2026-50275The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1…0.7%높음7.5
CVE-2026-68496The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLengt…0.7%높음7.5
CVE-2026-68495The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength…0.7%높음7.5
CVE-2026-68956Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated r…0.7%높음7.1
CVE-2026-57173vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling p…0.7%보통6.5
CVE-2026-93838SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() th…0.7%높음8.2
CVE-2026-1168GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 1…0.6%높음7.5
CVE-2025-14871GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 1…0.6%높음7.5
CVE-2026-94613authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated a…0.6%높음7.5
CVE-2026-94624vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector i…0.6%높음8.7
CVE-2026-59990Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and …0.6%높음7.5
CVE-2026-82399CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, an…0.6%높음7.5
CVE-2026-84447libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and ide…0.6%높음7.5
CVE-2026-91149A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating a…0.6%높음7.5
CVE-2026-91080webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unau…0.6%높음8.7
CVE-2026-93572A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability…0.6%높음7.5
CVE-2026-50270dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TR…0.6%높음7.5
CVE-2026-65654github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local…0.6%높음8.7
CVE-2026-54156node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alre…0.5%높음7.5
CVE-2026-54135AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4…0.6%높음7.5
CVE-2026-103471restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote una…0.6%높음8.7
CVE-2026-75516The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with Rabbit…0.5%높음8.7
CVE-2026-82439Description The DRPC server kept a map from function name to request queue and created an entry the first time…0.5%심각9.8
CVE-2026-103042LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started wit…0.5%높음8.7
CVE-2026-77528Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to …0.5%보통5.3
CVE-2026-93309A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown function…0.5%낮음2.1
CVE-2026-93308A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functio…0.5%낮음2.1
CVE-2026-76716Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized acce…0.5%보통5.3
CVE-2026-81176Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficien…0.5%보통5.3
CVE-2026-82728Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP se…0.5%높음8.2
CVE-2026-89425UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for it…0.5%높음7.5
CVE-2026-45763Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.5%보통5.9
CVE-2026-77281Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configur…0.5%보통6.5
CVE-2026-57497webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule()…0.5%보통5.3
CVE-2026-91865A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references …0.5%높음7.5
CVE-2026-91864A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copi…0.5%높음7.5
CVE-2026-91866A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amoun…0.5%높음7.5
CVE-2026-69147vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Co…0.5%보통6.5
CVE-2026-69218Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 H…0.5%높음7.5
CVE-2026-69203Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 ena…0.5%높음7.5
CVE-2026-45768Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.5%높음7.5
CVE-2026-67230RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web ST…0.5%보통6.3
CVE-2026-103261Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing …0.5%보통6.9
CVE-2026-54873Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impa…0.5%높음7.5
CVE-2026-92003Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two …0.4%보통6.9
CVE-2026-69202Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control win…0.4%높음7.5
CVE-2026-53752docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX…0.4%높음7.5
CVE-2026-54716Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0…0.5%높음7.5
CVE-2026-45766Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%높음7.5
CVE-2026-45765Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%높음7.5
CVE-2026-13260IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient vali…0.4%높음7.5
CVE-2026-103472restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the …0.4%높음8.7
CVE-2026-87742A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of …0.4%높음7.5
CVE-2026-17508In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cos…0.4%보통5.3
CVE-2026-90584A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function…0.4%보통5.5
CVE-2026-61652Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion…0.4%높음8.7
CVE-2026-104845Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities.…0.4%높음7.5
CVE-2026-77409RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confi…0.4%높음8.2
CVE-2026-77403RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a…0.4%높음8.9
CVE-2026-91990Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits mu…0.4%높음8.7
CVE-2026-96288Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Er…0.4%높음8.2
CVE-2026-91137Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Exce…0.4%높음8.7
CVE-2026-94657Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issu…0.4%높음8.2
CVE-2026-66331Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered t…0.4%보통6.9
CVE-2026-94648Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue …0.4%높음8.2
CVE-2026-94644Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue a…0.4%높음8.2
CVE-2026-94656Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue …0.4%높음8.2
CVE-2026-94655Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apac…0.4%높음8.2
CVE-2026-96990Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issu…0.4%높음8.2
CVE-2026-94638Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue a…0.4%보통6.3
CVE-2026-61373Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServe…0.4%높음8.7
CVE-2026-94645Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulne…0.4%높음8.2
CVE-2026-66054Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplif…0.4%보통6.9
CVE-2026-63772Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue af…0.4%높음8.7
CVE-2026-82458Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerabilit…0.4%높음8.7
CVE-2026-94639improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught ex…0.4%높음8.2
CVE-2026-94634Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vu…0.4%높음8.2
CVE-2026-94635Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vuln…0.4%높음8.7
CVE-2026-94002Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD vers…0.4%높음7.5
CVE-2026-100656Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. T…0.4%높음8.7
CVE-2026-61541Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application r…0.4%보통6.9
CVE-2026-91043Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP…0.4%높음8.2
CVE-2026-86513A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the f…0.4%보통5.5
CVE-2026-61629nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n m…0.4%높음7.5
CVE-2026-82753Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_se…0.4%높음8.2
CVE-2026-10832A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resou…0.4%보통5.9
CVE-2026-85449MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT me…0.4%높음8.7
CVE-2026-105127LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and rese…0.4%보통6.9
CVE-2026-57224Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%보통6.5
CVE-2026-84784Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoidin…0.4%높음7.5
CVE-2026-85219Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attack…0.4%낮음3.7
CVE-2026-85220A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to exec…0.4%낮음3.7
CVE-2026-53941Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clust…0.4%보통6.9
CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursio…0.4%높음8.7
CVE-2026-92961vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray construc…0.4%높음8.7
CVE-2023-54394PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allo…0.4%보통5.3
CVE-2026-86040libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accep…0.4%높음7.5
CVE-2026-91987atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that re…0.4%높음7.1
CVE-2026-85107A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourc…0.4%보통5.3
CVE-2026-88382hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggr…0.4%높음7.5
CVE-2026-91970Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to…0.4%높음7.1
CVE-2026-85582SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic…0.4%높음7.1
CVE-2026-92284Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/cad…0.4%보통6.9
CVE-2026-85664Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_…0.4%높음8.7
CVE-2026-69213Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outboun…0.4%높음7.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.