CWE-95 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-95 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2025-24893XWiki Platform is a generic wiki platform offering runtime services for applications built on top of…99.9%심각9.8● 실제 악용이 확인됨CVE-2024-36401GeoServer is an open source server that allows users to share and edit geospatial data. Prior to ver…99.8%심각9.8● 실제 악용이 확인됨CVE-2026-33017Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to …24.8%심각9.3● 실제 악용이 확인됨CVE-2023-7101Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::Par…19.1%높음7.8CVE-2026-48273ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…1.9%심각9.9CVE-2026-100741Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versio…1.7%심각9.8CVE-2026-76190ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…1.0%높음8.6CVE-2026-19780Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac…1.0%높음8.8
전체 목록
26건
CVE-2026-78847An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using …0.9%심각9.8
CVE-2026-61667DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.2…0.7%심각9.9
CVE-2025-53837XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML…0.6%심각9.9
CVE-2026-57149plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard…0.6%심각9.9
CVE-2026-80351Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache…0.5%심각9.8
CVE-2026-79678A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input …0.5%높음8.1
CVE-2026-45579DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.2…0.4%심각9.9
CVE-2026-55094Taskcluster is the task execution framework that supports Mozilla's continuous integration and release process…0.4%높음8.7
CVE-2026-78550The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an…0.4%보통6.6
CVE-2026-76974SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker …0.3%보통5.3
CVE-2026-82789An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONP…0.3%높음8.7
CVE-2026-85165n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread…0.3%높음7.2
CVE-2026-63325Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of …0.2%높음7.8
CVE-2026-100840MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that res…0.2%높음8.5
CVE-2026-101861Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py tha…0.2%낮음2.1
CVE-2026-69662The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.0.2%낮음2.1
CVE-2024-42002A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command…0.2%높음8.6
CVE-2026-100842MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scri…0.1%높음7.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.