$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-798 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-798

CWE-798 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

9.8ATCWE-798● 실제 악용이 확인됨CVE-2022-26138Atlassian · ConfluenceThe Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluenc…98.2%심각9.89.8DLCWE-798● 실제 악용이 확인됨CVE-2024-3272D-Link · Multiple NAS Devices** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been fou…98.0%심각9.89.8CICWE-912● 실제 악용이 확인됨CVE-2024-20439Cisco · Smart Licensing UtilityA vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attac…97.1%심각9.89.8GLCWE-321● 실제 악용이 확인됨CVE-2025-30406Gladinet · CentreStackGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vuln…94.3%심각9.89.1SOCWE-798● 실제 악용이 확인됨CVE-2024-28987SolarWinds · Web Help DeskThe SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, all…93.3%심각9.19.8EYCWE-798● 실제 악용이 확인됨CVE-2020-8657EyesOfNetwork · EyesOfNetworkAn issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as E…91.9%심각9.86.8ZOCWE-78● 실제 악용이 확인됨CVE-2022-28810Zoho · ManageEngineZoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator t…71.0%보통6.87.1GLCWE-798● 실제 악용이 확인됨CVE-2025-14611Gladinet · CentreStack and TriofoxGladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their …53.3%높음7.1

전체 목록

74건

CVE-2021-44207악용 확인Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.17.6%높음8.1
CVE-2026-22769악용 확인Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerab…13.3%심각10.0
CVE-2019-6693랜섬웨어 악용Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow …5.8%보통6.5
CVE-2023-6448악용 확인Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrat…2.1%심각9.8
CVE-2026-54767WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_…0.8%심각9.1
CVE-2026-57147PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns t…0.8%심각9.8
CVE-2026-65113NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-…0.6%심각9.8
CVE-2026-76708A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operati…0.6%심각9.8
CVE-2026-47116LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account password…0.5%심각9.2
CVE-2026-93970A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing …0.5%보통6.9
CVE-2026-93969A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_d…0.5%보통6.9
CVE-2026-101052A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown proc…0.5%보통5.5
CVE-2026-84034IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_asses…0.4%높음8.8
CVE-2026-16141OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client ca…0.4%높음8.1
CVE-2026-86520Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for eve…0.4%높음8.7
CVE-2026-92787Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attacker…0.4%심각9.3
CVE-2026-57148PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls bac…0.4%심각9.8
CVE-2026-86464In the current development version of Eclipse aeriOS, for which no official release has yet been published, th…0.4%심각9.9
CVE-2026-85146SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica…0.4%심각9.3
CVE-2026-85148SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica…0.4%심각9.3
CVE-2026-85391Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthentic…0.3%심각9.3
CVE-2026-77847Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vul…0.3%높음7.1
CVE-2026-96587The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code…0.3%심각10.0
CVE-2026-81440Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vul…0.3%높음7.3
CVE-2026-77960Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for eve…0.3%보통6.9
CVE-2026-79740Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.3%높음7.5
CVE-2026-79738Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.3%높음7.5
CVE-2026-85083The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with p…0.3%높음7.0
CVE-2026-90509A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function Expo…0.3%보통5.5
CVE-2026-75940A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese mark…0.3%심각9.3
CVE-2026-86276A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This is…0.3%보통5.5
CVE-2026-63406AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, t…0.3%보통5.9
CVE-2026-86673A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca4…0.3%보통5.5
CVE-2026-17038DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credenti…0.3%보통6.9
CVE-2026-80134Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.3%높음7.7
CVE-2026-85149SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthentica…0.2%보통6.9
CVE-2026-96548A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an u…0.3%낮음2.9
CVE-2026-79950Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%높음7.5
CVE-2026-68950The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as roo…0.2%높음8.7
CVE-2026-67104HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an una…0.2%보통5.3
CVE-2026-85451MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper compo…0.2%높음7.1
CVE-2026-100294In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that a…0.2%높음8.7
CVE-2026-86150A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the fi…0.2%낮음2.0
CVE-2026-7193A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows…0.2%높음8.6
CVE-2026-80170Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통6.5
CVE-2026-75754Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Creden…0.2%심각10.0
CVE-2026-92928OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery accou…0.2%보통6.5
CVE-2026-66890The affected products use hard-coded credentials, which could allow remote access to files with root privilege…0.2%심각9.4
CVE-2026-79731Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통4.4
CVE-2026-86555The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is store…0.2%보통6.2
CVE-2026-37152TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.0.2%심각9.8
CVE-2026-81640An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or elim…0.2%높음8.7
CVE-2026-55395Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9…0.2%심각9.4
CVE-2026-79959The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by t…0.2%높음7.0
CVE-2026-102666The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attack…0.2%보통6.9
CVE-2026-103097An API key is hardcoded and retrievable from the application package. Since Android applications can be revers…0.2%높음7.5
CVE-2026-103096API key is hardcoded and retrievable from the application package. Since Android applications can be reverse e…0.2%높음7.5
CVE-2026-27874: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default…0.1%보통5.0
CVE-2026-13043A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint…0.1%심각9.3
CVE-2026-94592Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superu…0.1%높음8.6
CVE-2026-93290Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials t…0.1%보통6.8
CVE-2026-17644IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized…0.1%높음8.8
CVE-2026-5522IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cry…0.1%보통6.7
CVE-2026-27873- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This is…0.1%보통5.6
CVE-2026-105147A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT…보통5.5
CVE-2026-105141A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function ge…보통5.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.