$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-918 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-918

CWE-918 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

8.2IVCWE-918● 랜섬웨어 캠페인에 사용됨CVE-2024-21893Ivanti · Connect Secure, Policy Secure, and NeuronsA server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.…100.0%높음8.29.0APCWE-918● 랜섬웨어 캠페인에 사용됨CVE-2021-40438Apache · ApacheA crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by…100.0%심각9.09.1MICWE-918● 랜섬웨어 캠페인에 사용됨CVE-2021-34473Microsoft · Exchange ServerMicrosoft Exchange Server Remote Code Execution Vulnerability100.0%심각9.19.8VMCWE-918● 랜섬웨어 캠페인에 사용됨CVE-2021-21985VMware · vCenter ServerThe vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input valid…100.0%심각9.89.1MICWE-918● 랜섬웨어 캠페인에 사용됨CVE-2021-26855Microsoft · Exchange ServerMicrosoft Exchange Server Remote Code Execution Vulnerability100.0%심각9.18.8MICWE-918● 랜섬웨어 캠페인에 사용됨CVE-2022-41040Microsoft · Exchange ServerMicrosoft Exchange Server Elevation of Privilege Vulnerability100.0%높음8.89.8F5CWE-918● 랜섬웨어 캠페인에 사용됨CVE-2021-22986F5 · BIG-IP and BIG-IQ Centralized ManagementOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x befo…99.9%심각9.87.5OMCWE-918● 실제 악용이 확인됨CVE-2021-22054Omnissa · Workspace One UEMVMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prio…99.7%높음7.5

전체 목록

120건

CVE-2021-21311악용 확인Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4…98.5%높음7.2
CVE-2025-61884랜섬웨어 악용Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported…95.9%높음7.5
CVE-2023-41763악용 확인Skype for Business Elevation of Privilege Vulnerability90.4%보통5.3
CVE-2026-20230악용 확인A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager …88.2%높음8.6
CVE-2021-21973악용 확인The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper valida…88.0%보통5.3
CVE-2020-7796악용 확인Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet J…84.4%심각9.8
CVE-2019-9621악용 확인Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 …81.0%높음7.5
CVE-2021-21975랜섬웨어 악용Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malic…77.9%높음7.5
CVE-2016-3718악용 확인The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers t…76.7%보통5.5
CVE-2021-22175악용 확인When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in…53.4%심각9.8
CVE-2021-39935악용 확인An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all vers…35.6%높음7.5
CVE-2021-27103랜섬웨어 악용Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The …11.4%심각9.8
CVE-2026-64849악용 확인MLflow is an open source AI engineering platform for agents, large language models, and machine learning model…9.8%심각9.3
CVE-2026-83548악용 확인A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an uninten…8.8%심각10.0
CVE-2026-15409랜섬웨어 악용A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place int…6.8%심각10.0
CVE-2026-49869악용 확인Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilte…2.1%심각10.0
CVE-2026-85917Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges o…1.0%높음7.5
CVE-2026-77987A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise …0.9%심각9.3
CVE-2026-69683Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose in…0.8%높음7.7
CVE-2026-82013Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu…0.8%심각9.9
CVE-2026-81999Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that coul…0.8%높음8.7
CVE-2026-69361Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoof…0.8%보통6.5
CVE-2026-82000Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that coul…0.7%심각9.6
CVE-2026-66304Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose informati…0.7%높음7.5
CVE-2026-19233CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command executi…0.7%높음8.6
CVE-2026-54734Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate …0.6%심각10.0
CVE-2026-57866Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permiss…0.6%높음8.8
CVE-2026-95679MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying …0.6%보통6.9
CVE-2026-55864GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST…0.6%높음7.8
CVE-2026-54048Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0…0.6%보통5.3
CVE-2026-69904Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose in…0.6%낮음3.5
CVE-2026-80150Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware version…0.6%높음7.7
CVE-2026-80149Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware version…0.6%높음7.7
CVE-2026-80148Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware version…0.6%높음7.7
CVE-2026-51997An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the…0.5%높음8.8
CVE-2026-56660GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS.…0.5%심각9.1
CVE-2026-101898Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 reque…0.5%높음7.0
CVE-2026-75885A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/sam…0.5%심각9.3
CVE-2026-94040A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMPr…0.5%보통5.5
CVE-2026-86237A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function tes…0.5%보통5.5
CVE-2026-90818A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacte…0.5%낮음2.1
CVE-2026-95656A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the functi…0.5%보통5.5
CVE-2026-94038A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Han…0.5%보통5.5
CVE-2026-92566DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpo…0.5%높음8.8
CVE-2026-54637Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, th…0.5%보통5.5
CVE-2026-76900CordysCRM is an open source AI-powered customer relationship management system that supports private deploymen…0.5%보통6.8
CVE-2026-92380A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the…0.5%보통5.5
CVE-2026-68536Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also …0.5%심각9.8
CVE-2026-94039A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of th…0.5%보통5.5
CVE-2026-90710A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of t…0.5%보통5.5
CVE-2026-45723Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementSe…0.5%낮음2.7
CVE-2026-85608Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/down…0.5%높음8.7
CVE-2026-61793Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes th…0.5%보통6.9
CVE-2026-77866Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated U…0.5%심각9.0
CVE-2026-61749InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author…0.5%보통6.5
CVE-2026-86806A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. Th…0.5%보통6.9
CVE-2026-54339Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/disc…0.5%높음7.7
CVE-2026-71198In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP lo…0.4%높음7.0
CVE-2026-77274MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to …0.5%높음8.8
CVE-2026-75511Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat w…0.5%보통5.3
CVE-2026-59823LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an auth…0.4%보통5.3
CVE-2026-100893A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the functio…0.5%보통5.5
CVE-2023-54402iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote u…0.4%높음8.7
CVE-2026-94028A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_d…0.4%낮음2.1
CVE-2026-54507Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior …0.4%높음8.4
CVE-2026-88056Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript…0.4%높음8.6
CVE-2026-92719Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, a…0.4%높음8.7
CVE-2026-63443Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.…0.4%높음8.3
CVE-2026-85666OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery…0.4%높음8.7
CVE-2026-92815changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthentic…0.4%높음8.7
CVE-2026-92576HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component …0.4%심각9.2
CVE-2026-79764Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. …0.4%높음7.7
CVE-2026-62282OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and…0.4%보통6.5
CVE-2025-56563A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The scrip…0.4%심각9.8
CVE-2026-54918NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox…0.4%보통5.3
CVE-2026-55473HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockC…0.4%보통6.0
CVE-2026-54452safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go…0.4%보통6.3
CVE-2026-91966AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_av…0.4%보통6.9
CVE-2026-92215A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the functi…0.4%보통6.9
CVE-2026-79913Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server…0.4%보통6.5
CVE-2026-86321A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function Jso…0.4%보통5.5
CVE-2026-85732oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/…0.4%보통4.7
CVE-2026-57126PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _hos…0.4%높음8.5
CVE-2026-56734Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentic…0.4%보통5.3
CVE-2026-85673LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal med…0.4%높음8.7
CVE-2026-86240A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of th…0.4%낮음2.0
CVE-2026-59973FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 unt…0.4%높음8.5
CVE-2026-58196ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) serve…0.4%보통4.7
CVE-2026-88403A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated at…0.4%보통6.5
CVE-2026-54077ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arc…0.4%높음7.1
CVE-2026-104459YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unau…0.4%보통6.9
CVE-2026-81446Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF…0.4%높음7.4
CVE-2026-86590In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endp…0.4%보통6.3
CVE-2026-82757Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an att…0.4%보통6.3
CVE-2026-101913ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, t…0.4%보통6.3
CVE-2026-101910ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until …0.4%보통6.9
CVE-2026-86173MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that al…0.4%높음8.7
CVE-2026-55177CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior…0.4%높음7.6
CVE-2026-103957Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authe…0.4%높음8.2
CVE-2026-94401MISP has a file-handling vulnerability that could let certain authenticated users make the server read files o…0.4%높음8.3
CVE-2026-54688mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilitie…0.4%보통6.5
CVE-2026-89049A server-side request forgery issue due to improper validation of equivalent address representations in the po…0.4%높음8.5
CVE-2026-81213IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from inter…0.4%높음8.6
CVE-2026-82375Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing righ…0.4%높음7.4
CVE-2026-91079Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to…0.4%보통6.3
CVE-2026-92527A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callback…0.4%낮음2.1
CVE-2026-82097IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary c…0.4%높음8.8
CVE-2026-54546CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior…0.4%보통5.0
CVE-2026-91938Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and …0.3%높음7.6
CVE-2026-86119Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/im…0.3%심각9.2
CVE-2026-74768Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vuln…0.3%보통4.1
CVE-2026-93506A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /med…0.4%보통5.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.