CWE-78 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-78 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2014-6271GNU Bash through 4.3 processes trailing strings after function definitions in the values of environm…100.0%심각9.8● 실제 악용이 확인됨CVE-2021-1498Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an …100.0%심각9.8● 실제 악용이 확인됨CVE-2019-16920Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652,…100.0%심각9.8● 실제 악용이 확인됨CVE-2022-44877login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote…100.0%심각9.8● 실제 악용이 확인됨CVE-2020-8515DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.…100.0%심각9.8● 실제 악용이 확인됨CVE-2020-9054Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-au…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2024-4577In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and …100.0%심각9.8● 실제 악용이 확인됨CVE-2020-25506D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi compon…100.0%심각9.8
전체 목록
120건
CVE-2019-10149악용 확인A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in delive…100.0%심각9.8
CVE-2022-30525악용 확인A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 throug…99.9%심각9.8
CVE-2018-10562랜섬웨어 악용An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in…99.9%심각9.8
CVE-2014-7169악용 확인GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the…99.9%심각9.8
CVE-2021-1497악용 확인Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenti…99.9%심각9.8
CVE-2026-10520악용 확인An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows…99.9%심각10.0
CVE-2024-45519악용 확인The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 befo…99.9%심각9.8
CVE-2021-36260악용 확인A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input v…99.9%심각9.8
CVE-2021-35394악용 확인Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually c…99.9%심각9.8
CVE-2022-46169악용 확인Cacti is an open source platform which provides a robust and extensible operational monitoring and fault manag…99.8%심각9.8
CVE-2019-15107랜섬웨어 악용An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injecti…99.7%심각9.8
CVE-2025-48703악용 확인CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution…99.7%심각9.0
CVE-2014-6278악용 확인GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment vari…99.6%높음8.8
CVE-2020-16846악용 확인An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the…99.6%심각9.8
CVE-2023-28771악용 확인Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series fir…99.3%심각9.8
CVE-2022-36804악용 확인Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version…99.2%높음8.8
CVE-2020-11978악용 확인An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability…99.2%높음8.8
CVE-2020-7247악용 확인smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote att…99.0%심각9.8
CVE-2019-3929악용 확인The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.…99.0%심각9.8
CVE-2024-50603악용 확인An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper …98.5%심각9.8
CVE-2024-9463악용 확인An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to r…98.5%심각9.9
CVE-2019-11539랜섬웨어 악용In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1…98.5%높음7.2
CVE-2024-12987악용 확인A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affec…98.2%보통6.9
CVE-2022-29303악용 확인SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.98.0%심각9.8
CVE-2023-25280악용 확인OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to roo…97.9%심각9.8
CVE-2021-45382악용 확인A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW…97.8%심각9.8
CVE-2021-36380악용 확인Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipA…97.6%심각9.8
CVE-2020-1956악용 확인Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command…97.3%높음8.8
CVE-2019-20500악용 확인D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save…97.1%높음7.8
CVE-2020-25223악용 확인A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, a…96.8%심각9.8
CVE-2021-22502악용 확인Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version …96.7%심각9.8
CVE-2018-6530랜섬웨어 악용OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMW…96.7%심각9.8
CVE-2017-3506악용 확인Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)…96.3%높음7.4
CVE-2019-1652악용 확인A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN…95.9%높음7.2
CVE-2024-1212악용 확인Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling a…95.4%심각9.8
CVE-2024-9474랜섬웨어 악용A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with …94.8%보통6.9
CVE-2018-14933악용 확인upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the upl…94.9%심각9.8
CVE-2024-51378랜섬웨어 악용getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote a…94.7%심각9.8
CVE-2017-18368악용 확인The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a comm…94.4%심각9.8
CVE-2025-11953악용 확인The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces …94.0%심각9.8
CVE-2022-33891악용 확인The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With…93.2%높음8.8
CVE-2026-42271악용 확인LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to b…92.6%높음8.7
CVE-2022-26258악용 확인D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST t…92.0%심각9.8
CVE-2018-11138랜섬웨어 악용The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is acc…91.8%심각9.8
CVE-2026-1731랜섬웨어 악용BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critica…90.9%심각9.9
CVE-2021-21315악용 확인The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of f…90.7%높음7.8
CVE-2023-20273악용 확인A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker t…89.6%높음7.2
CVE-2019-17621악용 확인The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthent…89.6%심각9.8
CVE-2018-14839악용 확인LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote).…89.4%심각9.8
CVE-2024-8190악용 확인An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before all…88.5%높음7.2
CVE-2018-9276악용 확인An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System …87.0%높음7.2
CVE-2019-16057랜섬웨어 악용The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.86.5%심각9.8
CVE-2018-6961악용 확인VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the l…86.3%높음8.1
CVE-2025-64328악용 확인FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.3…84.6%높음8.6
CVE-2020-15415악용 확인On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload all…84.5%심각9.8
CVE-2020-12641악용 확인rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacha…84.3%심각9.8
CVE-2021-27561악용 확인Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/serv…82.9%심각9.8
CVE-2023-27992악용 확인The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AA…82.8%심각9.8
CVE-2023-43208랜섬웨어 악용NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. …82.7%심각9.8
CVE-2020-10987악용 확인The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute a…79.8%심각9.8
CVE-2024-8957악용 확인PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera d…79.7%높음7.2
CVE-2020-8816악용 확인Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHC…78.2%높음7.2
CVE-2020-10221악용 확인lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS c…77.1%높음8.8
CVE-2019-15949악용 확인Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as t…77.0%높음8.8
CVE-2023-44221악용 확인Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authent…76.3%높음7.2
CVE-2026-25089악용 확인A improper neutralization of special elements used in an os command ('os command injection') vulnerability in …76.1%심각9.8
CVE-2021-25298악용 확인Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/loca…75.1%높음8.8
CVE-2025-1316악용 확인Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to ach…74.5%심각9.3
CVE-2019-12991악용 확인Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (i…74.1%높음8.8
CVE-2023-47565악용 확인An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firm…73.3%높음8.8
CVE-2017-6334악용 확인dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to …72.6%높음8.8
CVE-2022-28810악용 확인Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute …71.0%보통6.8
CVE-2016-11021악용 확인setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS com…68.9%높음7.2
CVE-2017-6077악용 확인ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execu…68.7%심각9.8
CVE-2020-4428악용 확인IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute ar…61.7%심각9.1
CVE-2024-9380악용 확인An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a rem…59.7%높음7.2
CVE-2021-27104랜섬웨어 악용Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various a…56.7%심각9.8
CVE-2021-25297악용 확인Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/loca…56.7%높음8.8
CVE-2025-58034악용 확인An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [C…55.6%높음7.2
CVE-2023-49897악용 확인An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmwar…50.4%높음8.8
CVE-2021-40407악용 확인An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W …47.6%높음7.2
CVE-2026-39808악용 확인A improper neutralization of special elements used in an os command ('os command injection') vulnerability in …47.4%심각9.8
CVE-2023-39780악용 확인On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /s…39.5%높음8.8
CVE-2019-11001악용 확인On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin ca…37.5%높음7.2
CVE-2017-6884랜섬웨어 악용A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b…34.6%높음8.8
CVE-2020-2509악용 확인A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerabil…34.0%심각9.8
CVE-2025-9377악용 확인The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link …33.5%높음8.6
CVE-2018-19949랜섬웨어 악용If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNA…28.4%심각9.8
CVE-2024-11120악용 확인Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can…28.4%심각9.8
CVE-2019-19356악용 확인Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web managem…28.2%높음7.5
CVE-2025-54948악용 확인A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote…22.0%심각9.8
CVE-2024-40891악용 확인**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands…21.5%높음8.8
CVE-2020-9377악용 확인D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnera…21.3%높음8.8
CVE-2024-40890악용 확인**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the …20.7%높음8.8
CVE-2020-4006악용 확인VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a…17.3%심각9.1
CVE-2026-34197악용 확인Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache A…15.5%높음8.8
CVE-2022-20708악용 확인Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an …14.9%높음8.0
CVE-2024-12686악용 확인A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow …13.7%높음7.2
CVE-2026-73570악용 확인A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zi…11.7%높음8.9
CVE-2026-83549악용 확인Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…10.8%높음7.8
CVE-2024-6047악용 확인Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticat…10.1%심각9.8
CVE-2018-14558악용 확인An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firm…8.7%심각9.8
CVE-2026-25108악용 확인FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logg…5.2%높음8.7
CVE-2024-20399악용 확인A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administ…4.3%보통6.7
CVE-2021-20035악용 확인Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated a…4.2%보통6.5
CVE-2021-27102랜섬웨어 악용Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed…3.7%높음7.8
CVE-2025-8876악용 확인Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-c…3.4%심각9.4
CVE-2025-66644악용 확인Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through …3.4%심각9.8
CVE-2026-49869악용 확인Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilte…2.1%심각10.0
CVE-2026-16812악용 확인VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to acce…1.0%심각10.0
CVE-2025-1976악용 확인Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin priv…0.7%높음8.6
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.