$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-863 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-863

CWE-863 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

9.8ATCWE-863● 랜섬웨어 캠페인에 사용됨CVE-2023-22518Atlassian · Confluence Data Center and ServerAll versions of Confluence Data Center and Server are affected by this unexploited vulnerability. Th…100.0%심각9.89.8IVCWE-863● 랜섬웨어 캠페인에 사용됨CVE-2023-38035Ivanti · SentryA security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below,…100.0%심각9.89.8CACWE-74● 실제 악용이 확인됨CVE-2022-46169Cacti · CactiCacti is an open source platform which provides a robust and extensible operational monitoring and f…99.8%심각9.89.8APCWE-863● 실제 악용이 확인됨CVE-2024-38856Apache · OFBizIncorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.1…99.4%심각9.89.8QNCWE-863● 랜섬웨어 캠페인에 사용됨CVE-2019-7192QNAP · Photo StationThis improper access control vulnerability allows remote attackers to gain unauthorized access to th…88.1%심각9.810.0ADCWE-863● 실제 악용이 확인됨CVE-2025-54253Adobe · Experience Manager (AEM) FormsAdobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerabilit…88.0%심각10.09.1ADCWE-863● 실제 악용이 확인됨CVE-2026-71362Adobe · Commerce and Magento Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privileg…87.5%심각9.17.5DLCWE-863● 실제 악용이 확인됨CVE-2021-40655D-Link · DIR-605 RouterAn informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker ca…86.7%높음7.5

전체 목록

120건

CVE-2018-13382랜섬웨어 악용An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10…81.7%높음7.5
CVE-2023-24880랜섬웨어 악용Windows SmartScreen Security Feature Bypass Vulnerability78.0%보통4.4
CVE-2021-3493악용 확인The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the…49.2%높음7.8
CVE-2023-20269랜섬웨어 악용A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco…25.5%심각9.1
CVE-2021-3560악용 확인It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating t…23.7%높음7.8
CVE-2021-30533악용 확인Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attack…16.7%보통6.5
CVE-2023-21715악용 확인Microsoft Publisher Security Feature Bypass Vulnerability12.0%높음7.3
CVE-2026-42016악용 확인JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due t…8.6%높음8.8
CVE-2025-24200악용 확인An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPa…4.4%보통6.1
CVE-2025-55177악용 확인Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, W…4.3%보통5.4
CVE-2022-41091랜섬웨어 악용Windows Mark of the Web Security Feature Bypass Vulnerability1.8%보통5.4
CVE-2024-21287악용 확인Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Developmen…1.7%높음7.5
CVE-2025-21479악용 확인Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of …0.8%높음8.6
CVE-2025-21480악용 확인Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of …0.5%높음8.6
CVE-2026-86102An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with networ…1.8%심각9.3
CVE-2026-75745Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result i…1.2%심각10.0
CVE-2026-75723Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi…1.2%심각10.0
CVE-2026-75728Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbi…1.0%심각9.1
CVE-2026-68791Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over…1.0%높음8.6
CVE-2026-93643When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing s…1.0%심각9.8
CVE-2026-85978An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platf…0.9%심각10.0
CVE-2026-101880OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec…0.7%높음8.7
CVE-2026-55701The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0…0.7%보통6.9
CVE-2026-88616An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.…0.6%높음8.8
CVE-2026-77560Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames …0.6%높음8.1
CVE-2026-100560OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals f…0.6%높음7.7
CVE-2026-19232Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrar…0.6%심각9.9
CVE-2026-27552A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_…0.6%높음8.1
CVE-2026-6922The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization…0.6%높음7.1
CVE-2026-85619AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization c…0.5%높음7.7
CVE-2026-94609authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with dele…0.5%높음8.8
CVE-2026-95654Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the author…0.5%심각9.1
CVE-2026-86043Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthoriz…0.5%높음7.5
CVE-2026-52742GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose …0.5%보통5.1
CVE-2026-75608Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api…0.5%높음7.7
CVE-2026-61744InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacke…0.5%보통6.5
CVE-2026-88044rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.5%심각9.1
CVE-2026-101000A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of t…0.5%심각9.3
CVE-2026-77774Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature…0.5%높음8.6
CVE-2026-82431Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` …0.5%심각9.8
CVE-2026-77181Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement …0.5%심각9.8
CVE-2026-73668Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a give…0.5%심각9.8
CVE-2026-73579Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J o…0.5%심각9.8
CVE-2026-73370Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by…0.5%심각9.8
CVE-2026-55563Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_inte…0.5%높음8.9
CVE-2026-77108Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalati…0.5%높음7.5
CVE-2026-77111Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature…0.5%높음8.7
CVE-2026-55774OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with acces…0.4%낮음2.1
CVE-2026-65831ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database}…0.4%높음7.7
CVE-2026-55625GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /…0.5%보통4.9
CVE-2026-57133PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisona…0.4%높음8.8
CVE-2026-100744A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the fi…0.5%보통5.5
CVE-2026-62247Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtim…0.5%보통6.5
CVE-2026-85025IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary co…0.4%심각9.8
CVE-2026-86274A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects…0.4%보통5.5
CVE-2026-63443Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.…0.4%높음8.3
CVE-2026-93594ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-…0.4%높음7.1
CVE-2026-91998Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows atta…0.4%심각9.4
CVE-2026-75157Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` ins…0.4%미평가
CVE-2026-57125PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthentic…0.4%심각9.8
CVE-2026-95814Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restrictio…0.4%높음8.6
CVE-2026-77109Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalati…0.4%높음8.6
CVE-2026-52740GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP metho…0.4%보통5.3
CVE-2026-54076ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorizati…0.4%높음8.1
CVE-2026-82378Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthentica…0.4%심각9.0
CVE-2026-71543OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SS…0.4%높음7.5
CVE-2026-91164Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API tok…0.4%보통4.3
CVE-2026-92760Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allo…0.4%높음7.1
CVE-2026-76202Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalati…0.4%높음8.2
CVE-2026-57136PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/…0.4%높음8.8
CVE-2026-86437Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the se…0.4%높음8.6
CVE-2026-86665A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::…0.4%보통5.5
CVE-2026-95811Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.…0.4%보통6.5
CVE-2026-100721vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder co…0.4%심각9.5
CVE-2026-68570Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks …0.4%보통6.5
CVE-2026-73313XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider …0.4%높음7.6
CVE-2026-104480Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained a…0.4%심각9.4
CVE-2026-74769Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability …0.4%보통6.5
CVE-2026-67411RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, nat…0.4%보통6.0
CVE-2026-20072A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attack…0.4%보통4.9
CVE-2026-93954A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the funct…0.4%낮음2.1
CVE-2026-52819Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint acce…0.4%보통6.3
CVE-2026-89013Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attack…0.4%높음8.7
CVE-2026-92992A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unkno…0.4%낮음2.1
CVE-2026-95355Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attac…0.4%높음8.3
CVE-2026-75624IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote aut…0.4%높음8.8
CVE-2026-79767Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142…0.4%보통5.5
CVE-2026-85620Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not a…0.4%심각9.2
CVE-2026-76560A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous …0.4%높음7.5
CVE-2026-57137PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/…0.4%높음8.8
CVE-2026-61519Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a p…0.4%높음8.7
CVE-2026-103271Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visito…0.4%높음8.7
CVE-2026-90806A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function Bulk…0.4%보통5.3
CVE-2026-82062A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a …0.4%높음7.0
CVE-2026-73310XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers contro…0.4%높음8.2
CVE-2026-92774Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-…0.4%보통5.3
CVE-2026-13210GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.…0.4%높음7.7
CVE-2026-103547In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are …0.4%심각9.2
CVE-2026-72524Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks …0.4%높음8.8
CVE-2026-92402A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This is…0.4%보통5.3
CVE-2026-87481Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote atta…0.4%높음8.3
CVE-2026-61907An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An auth…0.4%보통4.3
CVE-2026-82432Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The…0.3%높음8.1
CVE-2026-104443YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authentic…0.4%높음7.2
CVE-2026-79708GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6…0.3%높음8.5
CVE-2026-93593ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL …0.4%높음8.6
CVE-2026-88008Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik…0.3%높음7.0
CVE-2026-87471Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who…0.3%미평가
CVE-2026-61709OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API cou…0.3%보통5.3
CVE-2026-90460An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication meth…0.3%높음7.6
CVE-2026-73236Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on…0.3%높음7.5
CVE-2026-78214An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determi…0.4%보통5.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.