CWE-807 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-807 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2026-21509Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attac…70.8%높음7.8● 실제 악용이 확인됨CVE-2026-34486Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914…6.6%높음7.5● 실제 악용이 확인됨CVE-2026-21514Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized …1.6%높음7.8CVE-2026-566819Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to re…1.0%높음7.3CVE-2026-84474A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-c…0.8%심각9.9CVE-2026-87858Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supp…0.8%높음7.2CVE-2026-85751Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and pr…0.6%심각9.8CVE-2026-94606authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik …0.5%높음8.9
전체 목록
26건
CVE-2026-59157webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP reques…0.5%보통6.5
CVE-2026-81179SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable pass…0.5%높음8.1
CVE-2026-566829Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.j…0.5%보통5.3
CVE-2026-82533DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP contro…0.4%심각9.4
CVE-2026-102117On deployments where the remote-support capability is licensed and enabled, an authenticated System Administra…0.4%높음7.2
CVE-2026-76147A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in t…0.4%보통5.9
CVE-2026-78427The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matc…0.4%보통4.3
CVE-2026-86863pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or re…0.3%심각9.3
CVE-2026-87479Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacke…0.3%높음8.3
CVE-2026-66768SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connec…0.3%심각9.0
CVE-2026-103923KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, K…0.3%낮음2.1
CVE-2026-88004Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint de…0.3%높음7.0
CVE-2026-79700Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuratio…0.3%보통6.9
CVE-2026-79701Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in an…0.3%보통6.9
CVE-2026-85602The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to …0.3%심각9.3
CVE-2026-103267Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that al…0.3%보통5.3
CVE-2026-101131A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown functi…0.1%낮음1.9
CVE-2026-101079A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the …0.1%낮음0.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.