CWE-88 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-88 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2016-10033The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attacker…99.7%심각9.8● 실제 악용이 확인됨CVE-2022-36804Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, fr…99.2%높음8.8● 실제 악용이 확인됨CVE-2026-24061telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for t…99.0%심각9.8● 실제 악용이 확인됨CVE-2024-41710A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 69…41.6%높음7.2● 실제 악용이 확인됨CVE-2026-86060RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin wit…6.4%심각9.2CVE-2026-54501Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-ho…1.2%심각9.4CVE-2026-89036Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users w…0.7%높음8.7CVE-2026-28197An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could su…0.7%심각9.4
전체 목록
51건
CVE-2026-84502A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is…0.6%심각9.9
CVE-2026-87900Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read…0.6%심각9.4
CVE-2026-100714Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling …0.5%심각9.4
CVE-2026-54337Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in th…0.4%심각9.8
CVE-2026-76866Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS inp…0.4%높음8.6
CVE-2026-8044CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exist…0.4%높음8.6
CVE-2026-76862Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcp…0.4%높음8.7
CVE-2026-103505Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs…0.4%보통6.9
CVE-2026-84256An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows re…0.4%높음7.7
CVE-2026-86864pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object reques…0.4%높음8.7
CVE-2026-86035Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 t…0.4%높음8.5
CVE-2026-102827simple-git, an interface for running git commands in any node.js application, enables applications to execute …0.4%높음8.1
CVE-2026-100369CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-lin…0.4%높음8.4
CVE-2026-90809A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._gu…0.3%보통6.9
CVE-2026-71377Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Comp…0.3%심각9.8
CVE-2026-84724An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsy…0.3%보통6.6
CVE-2026-85626git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log…0.3%높음8.7
CVE-2026-100561OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the …0.2%높음8.6
CVE-2026-94588In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionalit…0.2%보통4.4
CVE-2026-74237GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Clien…0.2%높음7.1
CVE-2026-90467aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to …0.2%보통6.3
CVE-2026-87818GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to rea…0.2%높음7.1
CVE-2023-22632PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.0.2%낮음2.7
CVE-2023-22631PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.0.2%낮음2.7
CVE-2026-0304A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low p…0.2%보통4.8
CVE-2026-86862pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of…0.2%높음7.1
CVE-2026-71465RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.exten…0.2%낮음3.1
CVE-2026-71464LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/J…0.2%낮음3.1
CVE-2026-55887MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP…0.2%높음8.7
CVE-2026-102904JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb…0.2%보통5.4
CVE-2026-87794bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that al…0.2%높음8.6
CVE-2026-93337NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN conne…0.2%높음8.5
CVE-2026-75131NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows…0.2%높음8.5
CVE-2026-89066Improper neutralization of special elements used in an OS command in the task synthesis component in projen be…0.2%높음8.4
CVE-2026-78635The Okta Privileged Access client URL handler does not insert an option terminator before appending the target…0.2%보통5.0
CVE-2026-90894Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/…0.1%높음7.8
CVE-2026-91784cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process nam…0.2%보통4.8
CVE-2026-55061uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in …0.2%낮음1.0
CVE-2026-19624A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.…0.1%높음7.8
CVE-2026-97662An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 m…0.1%보통6.9
CVE-2026-100570OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file …0.1%높음8.5
CVE-2026-11765Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BI…0.1%낮음3.3
CVE-2018-3856An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH…심각9.9
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.