CWE-862 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-862 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2021-39226Grafana is an open source data visualization platform. In affected versions unauthenticated and auth…99.9%높음7.3● 실제 악용이 확인됨CVE-2022-0543It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone t…99.4%심각10.0● 실제 악용이 확인됨CVE-2023-52163Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulner…96.9%높음8.8● 실제 악용이 확인됨CVE-2025-20362Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisc…87.1%높음8.6● 실제 악용이 확인됨CVE-2025-6205A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025…73.8%심각9.1● 실제 악용이 확인됨CVE-2021-30657A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.…68.5%보통5.5● 랜섬웨어 캠페인에 사용됨CVE-2024-57726SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges …66.6%심각9.9● 실제 악용이 확인됨CVE-2021-37976Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attac…19.9%보통6.5
전체 목록
120건
CVE-2021-30713악용 확인A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malic…7.0%높음7.8
CVE-2022-0492악용 확인A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c fu…5.5%높음7.8
CVE-2025-40602악용 확인A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 applianc…2.8%보통6.6
CVE-2026-84869악용 확인A condition in the ScreenConnect client may allow files to be transferred and executed through an active remot…0.9%심각9.9
CVE-2026-61410Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…1.3%심각9.4
CVE-2026-12645A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated a…1.2%심각9.9
CVE-2026-12646A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated a…1.2%심각9.9
CVE-2026-12647A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated a…1.2%심각9.9
CVE-2026-18851Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allow…1.0%높음8.8
CVE-2026-57131PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jo…1.0%심각9.8
CVE-2026-54629Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQ…1.0%높음7.5
CVE-2026-74909Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined …0.9%높음8.1
CVE-2026-92466zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.secu…0.8%높음8.7
CVE-2026-69641Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a …0.8%심각9.1
CVE-2026-69465Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a netw…0.8%높음8.8
CVE-2026-41871Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vuln…0.8%심각9.8
CVE-2026-69724Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a netw…0.8%높음8.8
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticat…0.8%심각9.1
CVE-2026-41869Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (N…0.8%심각9.1
CVE-2026-54237Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php a…0.8%심각9.3
CVE-2026-83941Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.0.7%심각9.9
CVE-2026-69380Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a …0.7%높음8.1
CVE-2026-89334The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerab…0.7%보통6.5
CVE-2026-41870Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamica…0.7%높음8.8
CVE-2026-61550Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JS…0.7%심각9.8
CVE-2026-73807The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An un…0.7%심각9.3
CVE-2026-75607Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.p…0.6%높음8.1
CVE-2026-43643Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the…0.6%높음8.7
CVE-2026-79920Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /…0.6%심각9.9
CVE-2026-79993The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing a…0.6%높음7.5
CVE-2026-81866Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that…0.6%낮음0.5
CVE-2026-86438Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, all…0.6%높음8.6
CVE-2026-9613The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in a…0.6%보통4.3
CVE-2026-54648CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc…0.6%보통6.5
CVE-2026-75030Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might…0.6%심각9.8
CVE-2026-85410The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder …0.6%높음8.1
CVE-2026-53625GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can …0.6%높음7.5
CVE-2026-4792The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. T…0.6%보통5.3
CVE-2026-82923The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check…0.6%심각9.8
CVE-2026-54671WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty res…0.6%높음8.8
CVE-2026-92729SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoint…0.5%높음8.8
CVE-2026-94501jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allo…0.5%높음8.7
CVE-2026-94412jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that all…0.5%높음8.7
CVE-2026-86591The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST rout…0.5%심각9.8
CVE-2026-93737Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing au…0.5%높음7.1
CVE-2026-82377Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog co…0.5%심각9.9
CVE-2026-89413The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu…0.5%높음8.1
CVE-2026-83621ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/syst…0.5%높음8.1
CVE-2026-92142Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access cont…0.5%미평가
CVE-2026-94411jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that all…0.5%높음8.7
CVE-2026-54519AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observabili…0.5%높음8.8
CVE-2026-69553Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.0.5%높음7.1
CVE-2026-78328A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management inter…0.5%심각9.1
CVE-2026-101000A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of t…0.5%심각9.3
CVE-2026-63116deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at s…0.5%높음8.8
CVE-2026-94541The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in a…0.5%심각9.8
CVE-2026-82885IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due …0.5%높음8.8
CVE-2026-56829Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/…0.5%높음8.1
CVE-2026-56825Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collectio…0.5%높음8.1
CVE-2026-56827Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewir…0.5%높음8.1
CVE-2026-63104Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated wo…0.5%높음7.2
CVE-2026-86059Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members …0.5%심각9.6
CVE-2026-57579Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, …0.5%높음7.5
CVE-2026-77426Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five aut…0.5%높음7.1
CVE-2026-63219GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2…0.5%높음8.6
CVE-2026-82684Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerabil…0.5%높음8.6
CVE-2026-9232The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …0.5%보통6.5
CVE-2026-17526Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a use…0.5%높음7.2
CVE-2026-100634SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC hand…0.5%보통5.3
CVE-2026-92761WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to p…0.4%높음8.7
CVE-2026-20324A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center…0.4%심각9.9
CVE-2026-59739Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attack…0.4%높음7.5
CVE-2026-57578DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-fin…0.4%심각9.2
CVE-2026-88944The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypas…0.5%보통4.3
CVE-2026-100744A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the fi…0.5%보통5.5
CVE-2026-84990ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/sys…0.5%높음8.8
CVE-2026-85400Backend administrators without system maintainer privileges were able to schedule any of the configuration:rea…0.4%높음7.5
CVE-2026-94496jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated u…0.5%높음8.7
CVE-2026-93455django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any…0.5%높음7.1
CVE-2026-91707The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc…0.5%보통5.3
CVE-2026-85058Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-control…0.5%높음7.5
CVE-2026-61594djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance.…0.4%심각9.1
CVE-2026-91048The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredS…0.4%미평가
CVE-2026-63330Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_str…0.4%높음7.7
CVE-2026-14349The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization …0.4%심각9.8
CVE-2026-86274A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects…0.4%보통5.5
CVE-2026-82041UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processC…0.4%보통6.5
CVE-2026-94001A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. Th…0.4%보통6.5
CVE-2026-94495jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allow…0.4%높음7.1
CVE-2026-49292Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled …0.4%미평가0.0
CVE-2026-57139PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src…0.4%심각9.8
CVE-2026-82433Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-lev…0.4%보통6.5
CVE-2026-79758Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. …0.4%보통5.4
CVE-2026-8030GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.…0.4%보통4.3
CVE-2026-87487Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had …0.4%높음8.3
CVE-2026-9615The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and includi…0.4%보통4.3
CVE-2026-54168Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior…0.4%보통6.5
CVE-2026-103490In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links0.4%높음7.2
CVE-2026-92245The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all v…0.4%높음7.5
CVE-2026-70178Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.0.4%높음8.5
CVE-2026-86777AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint…0.4%보통6.9
CVE-2026-92803LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthent…0.4%보통6.9
CVE-2026-84719A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copie…0.4%심각9.9
CVE-2026-52744GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-sugges…0.4%보통5.3
CVE-2026-54076ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorizati…0.4%높음8.1
CVE-2026-77132It has been discovered that several AJAX routes used for the backend localization wizard failed to perform aut…0.4%보통5.3
CVE-2026-61745InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ e…0.4%보통4.3
CVE-2026-93344MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking…0.4%높음7.1
CVE-2026-69190Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update…0.4%보통6.3
CVE-2026-94113Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerabilit…0.4%높음7.1
CVE-2026-61748InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print…0.4%보통4.3
CVE-2026-75017The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Pos…0.4%보통4.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.