$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-94 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-94

CWE-94 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

9.8MICWE-94● 실제 악용이 확인됨CVE-2015-1635Microsoft · HTTP.sysHTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows…100.0%심각9.89.8PHCWE-94● 실제 악용이 확인됨CVE-2017-9841PHPUnit · PHPUnitUtil/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to exe…100.0%심각9.89.8VMCWE-94● 랜섬웨어 캠페인에 사용됨CVE-2022-22954VMware · Workspace ONE Access and Identity ManagerVMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due t…100.0%심각9.88.8MICWE-94● 랜섬웨어 캠페인에 사용됨CVE-2025-49704Microsoft · SharePointImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an a…100.0%높음8.89.8LACWE-306● 랜섬웨어 캠페인에 사용됨CVE-2025-3248Langflow · LangflowLangflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endp…100.0%심각9.87.8PECWE-94● 실제 악용이 확인됨CVE-2021-22204Perl · ExiftoolImproper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows…100.0%높음7.88.8MICWE-94● 랜섬웨어 캠페인에 사용됨CVE-2012-0158Microsoft · MSCOMCTL.OCXThe (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in…100.0%높음8.89.8VTCWE-94● 실제 악용이 확인됨CVE-2022-22963VMware Tanzu · Spring CloudIn Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing fu…99.9%심각9.8

전체 목록

120건

CVE-2022-24816악용 확인JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing …99.9%심각10.0
CVE-2025-24893악용 확인XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any g…99.9%심각9.8
CVE-2024-36401악용 확인GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22…99.8%심각9.8
CVE-2025-32432악용 확인Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting…99.8%심각10.0
CVE-2023-3519랜섬웨어 악용Unauthenticated remote code execution99.7%심각9.8
CVE-2021-22205랜섬웨어 악용An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properl…99.7%심각10.0
CVE-2019-16759악용 확인vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/re…99.7%심각9.8
CVE-2022-22965악용 확인A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) …99.6%심각9.8
CVE-2024-4040악용 확인A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all pla…99.5%심각10.0
CVE-2024-23692랜섬웨어 악용Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerabilit…99.5%심각9.8
CVE-2017-7494랜섬웨어 악용Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerabi…99.4%심각9.8
CVE-2014-6287악용 확인The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x bef…99.3%심각9.8
CVE-2018-7602랜섬웨어 악용A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentiall…99.2%심각9.8
CVE-2021-44529랜섬웨어 악용A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user…99.1%심각9.8
CVE-2022-3236악용 확인A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sop…98.9%심각9.8
CVE-2008-4250악용 확인The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1,…98.8%심각9.8
CVE-2026-1281악용 확인A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code e…98.7%심각9.8
CVE-2026-1340악용 확인A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code e…98.6%심각9.8
CVE-2022-22947악용 확인In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection …98.3%심각10.0
CVE-2021-39144악용 확인XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerabilit…98.1%높음8.5
CVE-2023-25717악용 확인Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as de…98.1%심각9.8
CVE-2022-43769악용 확인Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow…97.7%높음7.2
CVE-2019-9082악용 확인ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution v…97.4%높음8.8
CVE-2024-56145악용 확인Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of…97.4%심각9.3
CVE-2025-54068악용 확인Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability all…97.1%심각9.2
CVE-2018-1273랜섬웨어 악용Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain …97.0%심각9.8
CVE-2023-33246악용 확인For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. …96.6%심각9.8
CVE-2009-1151악용 확인Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 a…96.6%심각9.8
CVE-2019-7609악용 확인Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. A…95.3%심각10.0
CVE-2017-9822랜섬웨어 악용DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible rem…94.8%높음8.8
CVE-2020-8243악용 확인A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacke…90.8%높음7.2
CVE-2025-37164악용 확인A remote code execution issue exists in HPE OneView.90.2%심각9.8
CVE-2017-8759악용 확인Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code r…88.7%높음7.8
CVE-2020-8644악용 확인PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.86.7%심각9.8
CVE-2025-4428악용 확인Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified pla…86.5%높음8.8
CVE-2019-4716악용 확인IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthent…86.4%심각9.8
CVE-2023-24955랜섬웨어 악용Microsoft SharePoint Server Remote Code Execution Vulnerability85.0%높음7.2
CVE-2013-3906악용 확인GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Offi…84.9%높음7.8
CVE-2019-10758악용 확인mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method…84.7%심각9.9
CVE-2019-0193악용 확인In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other…83.5%높음7.2
CVE-2023-22952악용 확인In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates…80.1%높음8.8
CVE-2013-4810악용 확인HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application …79.5%심각9.8
CVE-2025-6204악용 확인An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release …79.3%높음8.0
CVE-2012-0391악용 확인The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressio…75.6%심각9.8
CVE-2018-14667악용 확인The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserReso…74.2%심각9.8
CVE-2012-1535악용 확인Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.20…70.4%높음7.8
CVE-2009-0556악용 확인Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac,…67.3%높음8.8
CVE-2025-62593악용 확인Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be…62.5%심각9.4
CVE-2014-4148악용 확인win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server …59.9%높음8.8
CVE-2009-0557악용 확인Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in…53.0%높음7.8
CVE-2009-0238악용 확인Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewe…43.2%높음8.8
CVE-2021-22894악용 확인A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated a…41.3%높음8.8
CVE-2020-8218악용 확인A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI …32.3%높음7.2
CVE-2026-9198악용 확인IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPE…28.7%심각9.8
CVE-2024-21351악용 확인Windows SmartScreen Security Feature Bypass Vulnerability27.8%높음7.6
CVE-2026-33017악용 확인Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the…24.8%심각9.3
CVE-2026-60004악용 확인Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.24.0%심각9.8
CVE-2025-23209악용 확인Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is …21.8%높음8.1
CVE-2024-20359악용 확인A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that ha…19.4%보통6.0
CVE-2025-67038악용 확인An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write …19.3%심각9.8
CVE-2023-7101악용 확인Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is…19.1%높음7.8
CVE-2026-34197악용 확인Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache A…15.5%높음8.8
CVE-2021-22900악용 확인A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead …14.1%높음7.2
CVE-2026-15410랜섬웨어 악용Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identifie…11.8%높음7.2
CVE-2022-41223랜섬웨어 악용The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated at…10.7%보통6.8
CVE-2026-20045악용 확인A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Ses…4.5%심각9.8
CVE-2023-41179악용 확인A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), W…4.3%높음7.2
CVE-2023-6548악용 확인Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an att…3.2%높음8.8
CVE-2023-29492악용 확인Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of…2.7%심각9.8
CVE-2026-65660악용 확인Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized …2.1%높음8.8
CVE-2026-72530악용 확인A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to …1.7%심각9.5
CVE-2026-3910악용 확인Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execut…1.0%높음8.8
CVE-2025-1976악용 확인Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin priv…0.7%높음8.6
CVE-2026-69806Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate pr…1.8%높음7.0
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticate…1.3%심각9.8
CVE-2026-97160Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.…1.3%심각9.4
CVE-2026-89275Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulne…1.2%심각10.0
CVE-2026-84412Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulne…1.2%심각10.0
CVE-2026-75699Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulne…1.2%심각10.0
CVE-2026-73369Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulne…1.2%심각10.0
CVE-2026-75721Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulne…1.2%심각10.0
CVE-2026-75703Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulne…1.2%심각10.0
CVE-2026-58400GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2…1.2%심각9.1
CVE-2026-19804The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscripti…1.0%높음8.8
CVE-2026-51990An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute …1.0%심각9.8
CVE-2026-57131PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jo…1.0%심각9.8
CVE-2026-90817An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Im…1.0%심각9.8
CVE-2026-61552Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API w…0.9%높음7.2
CVE-2026-78463Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized atta…0.9%높음8.8
CVE-2026-85978An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platf…0.9%심각10.0
CVE-2026-88404A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/scr…0.9%심각9.8
CVE-2026-53710MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the…0.8%심각10.0
CVE-2026-84738The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its…0.8%심각9.1
CVE-2026-55107Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of …0.8%심각10.0
CVE-2026-83627The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Re…0.8%심각9.8
CVE-2026-92937vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The…0.8%심각10.0
CVE-2026-52098An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowI…0.8%심각9.8
CVE-2026-76551The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied t…0.8%높음7.2
CVE-2026-76550The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when wr…0.8%높음7.2
CVE-2026-54237Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php a…0.8%심각9.3
CVE-2026-78159The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and…0.8%심각9.8
CVE-2026-39117An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote…0.8%심각9.8
CVE-2026-73453An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve a…0.7%심각9.5
CVE-2026-54612Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1…0.8%높음8.8
CVE-2026-73456Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interfa…0.7%심각9.2
CVE-2026-92229The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable…0.7%심각9.1
CVE-2026-93603vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of …0.7%심각10.0
CVE-2026-79310webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked i…0.7%높음8.5
CVE-2026-102097Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Emai…0.7%높음7.2
CVE-2026-96658A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code exec…0.7%심각9.9
CVE-2026-75031In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the …0.7%심각9.8
CVE-2026-47252Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPD…0.7%심각9.0
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.