통합 검색

보안 뉴스, CVE, 제품명, KISA 공지와 브리핑을 한 번에 검색합니다.

실제 악용” 검색 결과 38서버측 검색 · 카테고리별 최대 20

보안 뉴스 3건

취약점 20건

긴급실제 악용
CVE-2024-3400

Palo Alto Networks PAN-OS Command Injection Vulnerability

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

긴급실제 악용
CVE-2021-44228

Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vuln...

긴급실제 악용
CVE-2019-11510

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

긴급실제 악용
CVE-2024-23897

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

긴급실제 악용
CVE-2023-22518

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net dom...

긴급실제 악용
CVE-2023-35082

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

긴급실제 악용
CVE-2023-35078

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

긴급실제 악용
CVE-2023-27350

PaperCut MF/NG Improper Access Control Vulnerability

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

긴급실제 악용
CVE-2023-1671

Sophos Web Appliance Command Injection Vulnerability

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

긴급실제 악용
CVE-2022-26134

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

긴급실제 악용
CVE-2022-29464

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 a...

긴급실제 악용
CVE-2021-22005

VMware vCenter Server File Upload Vulnerability

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

긴급실제 악용
CVE-2021-26084

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

긴급실제 악용
CVE-2021-35464

ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier

긴급실제 악용
CVE-2021-34473

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

긴급실제 악용
CVE-2021-21985

VMware vCenter Server Improper Input Validation Vulnerability

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

긴급실제 악용
CVE-2021-1498

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

긴급실제 악용
CVE-2020-5902

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

긴급실제 악용
CVE-2019-19781

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

긴급실제 악용
CVE-2018-13379

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

일일 보안현황 15건

298월

8월 29일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.

8월 29일 · AM 07:31조회 4
288월

8월 28일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.

8월 28일 · AM 07:30조회 2
278월

8월 27일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.

8월 27일 · AM 07:30조회 3
258월

8월 25일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.

8월 25일 · AM 07:30조회 4
248월

8월 24일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.

8월 24일 · AM 07:30조회 5
208월

8월 20일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.

8월 20일 · AM 07:30조회 6
198월

8월 19일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 2건을 먼저 다룹니다.

8월 19일 · AM 07:31조회 6
188월

8월 18일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.

8월 18일 · AM 07:31조회 11
178월

8월 17일 일일 보안현황

오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.

8월 17일 · AM 07:30조회 5
108월

8월 10일 일일 보안 브리핑

공개 시점이 아니라 실제 악용·공식 확인·공격 조건·수정 기준을 근거로 중요한 변화 3건을 선별했습니다.

8월 10일 · AM 07:30조회 2
207월

7월 14일~7월 20일 주간 보안 브리핑

최근 7일 CISA KEV 신규 등록은 9건으로, 직전 7건보다 2건(28.6%) 증가했습니다. 실제 악용 확인 항목이 늘어 KEV 대상 자산의 조치 우선순위를 높여야 합니다. 전체 신규 CVE 중 긴급·높음 비중은 48.4%로 직전 49.9%보다 1.5%p 하락했습니다.

7월 20일 · AM 08:42조회 5
167월

7월 10일~7월 16일 주간 보안 브리핑

최근 7일 CISA KEV 신규 등록은 9건으로, 직전 4건보다 5건(125.0%) 증가했습니다. 실제 악용 확인 항목이 늘어 KEV 대상 자산의 조치 우선순위를 높여야 합니다. 전체 신규 CVE 중 긴급·높음 비중은 58.0%로 직전 51.2%보다 6.8%p 상승했습니다.

7월 16일 · AM 07:48조회 10