CWE-943 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-943 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-62906Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows…0.7%높음7.4CVE-2026-93760Mongoid does not restrict which query operators may come from caller-supplied filter data when an ap…0.5%높음8.3CVE-2025-60357AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via …0.4%높음8.1CVE-2026-20284A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to co…0.4%심각9.1CVE-2026-55253LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to l…0.4%높음7.7CVE-2026-100631Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.…0.4%높음8.7CVE-2026-73976djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2,…0.4%높음7.1CVE-2026-88024Improper neutralization of special elements in data query logic in the GridFS component of the Mongo…0.3%보통6.1
전체 목록
31건
CVE-2026-88025Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driv…0.3%보통6.1
CVE-2026-88023Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Lib…0.3%보통6.1
CVE-2026-88022Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cau…0.3%높음8.4
CVE-2026-103258n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability…0.3%보통6.9
CVE-2026-73975djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authen…0.3%높음8.4
CVE-2026-91937Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queri…0.3%높음8.7
CVE-2026-96744Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoD…0.3%높음7.1
CVE-2026-81914Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names …0.3%보통4.3
CVE-2026-91133Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenti…0.3%보통6.5
CVE-2026-88031Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driv…0.3%보통6.1
CVE-2026-88036Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Drive…0.3%보통6.1
CVE-2026-88034Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Dri…0.3%보통6.1
CVE-2026-88030Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Dr…0.3%보통6.1
CVE-2026-88029Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python …0.3%보통6.1
CVE-2026-88033Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Dr…0.3%보통6.1
CVE-2026-88028Improper neutralization of special elements in data query logic in the polymorphic relation handling of the Mo…0.2%높음7.1
CVE-2026-85167n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Docume…0.2%보통6.3
CVE-2026-82060In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users …0.2%낮음2.3
CVE-2026-97228Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-…0.2%낮음2.7
CVE-2026-88027Improper neutralization of special elements in data query logic in the embedded-document relation handling of …0.2%높음7.1
CVE-2026-103289Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenti…0.2%높음7.1
CVE-2026-88026Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the Mo…0.2%높음7.1
CVE-2026-103250n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injectio…0.2%높음7.0
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.