μ·¨μ½ν λ컀 νκ²½μ ꡬμΆνμ¬, μ΄ν΄λλ₯Ό λμ΄κ³ , μ€μ΅μ ν΅ν΄ 보μ κΈ°μ μ μ΅νλ κ²μ λͺ©νλ‘ ν©λλ€.
Vulhub (https://vulhub.org/) μ μ°Έκ³ νμ¬, λ€μν 컨ν μ΄λ κΈ°λ°μ μ·¨μ½ν νκ²½μ ꡬμΆν©λλ€.
-
ActiveMQ β Java κΈ°λ° μ€νμμ€ λ©μμ§ λΈλ‘컀
- CVE-2016-3088 β ActiveMQ fileserver μμ νμΌ μ°κΈ° β RCE
- Contributor: @Roronoawjd | Risk Score: 9.8 (Reproducibility: 75%)
- CVE-2016-3088 β ActiveMQ fileserver μμ νμΌ μ°κΈ° β RCE
-
CouchDB β Erlang κΈ°λ° μ€νμμ€ λ¬Έμ μ§ν₯ NoSQL λ°μ΄ν°λ² μ΄μ€
- CVE-2017-12635 β CouchDB JSON νμ λΆμΌμΉλ₯Ό μ΄μ©ν μ격 κΆν μμΉ
- Contributor: @jason1343 | Risk Score: 9.8 (Reproducibility: 70%)
- CVE-2017-12635 β CouchDB JSON νμ λΆμΌμΉλ₯Ό μ΄μ©ν μ격 κΆν μμΉ
-
Django β Python κΈ°λ° μΉ νλ μμν¬
- CVE-2021-35042 β QuerySet.order_by() SQL Injection
- Contributor: @sj1226m | Risk Score: 7.5 (Reproducibility: 70%)
- CVE-2022-34265 β Trunc()/Extract() SQL Injection
- Contributor: @woohyun212 | Risk Score: 9.8 (Reproducibility: 85%)
- CVE-2022-34265 (2) β Trunc()/Extract() SQL Injection
- Contributor: @KMINGON | Risk Score: 9.8 (Reproducibility: 80%)
- CVE-2021-35042 β QuerySet.order_by() SQL Injection
-
Express β Node.js μΉ νλ μμν¬
- CVE-2024-29041 β Express μ€ν 리λ€μ΄λ νΈ μ·¨μ½μ
- Contributor: @j93es | Risk Score: 6.1 (Reproducibility: 75%)
- CVE-2024-29041 β Express μ€ν 리λ€μ΄λ νΈ μ·¨μ½μ
-
Elfinder β PHP κΈ°λ° μΉ νμΌ κ΄λ¦¬μ
- CVE-2021-32682 β ZIP μΈμ μ½μ
μ ν΅ν μ격 μ½λ μ€ν
- Contributor: @Tjdmin1 | Risk Score: 9.8 (Reproducibility: 75%)
- CVE-2021-32682 β ZIP μΈμ μ½μ
μ ν΅ν μ격 μ½λ μ€ν
-
Flask β Python κ²½λ μΉ νλ μμν¬
- SSTI β Server Side Template Injection
- Contributor: @positiveWand | Risk Score: 9.0 (Reproducibility: 75%)
- SSTI β Server Side Template Injection
-
Gradio β Python κΈ°λ° ML λͺ¨λΈ μΉ μΈν°νμ΄μ€ λΌμ΄λΈλ¬λ¦¬
- CVE-2023-51449 β /file μλν¬μΈνΈ λλ ν°λ¦¬ νΈλλ²μ€
- Contributor: @annseojin | Risk Score: 7.5 (Reproducibility: 80%)
- CVE-2023-51449 β /file μλν¬μΈνΈ λλ ν°λ¦¬ νΈλλ²μ€
-
GeoServer β Java κΈ°λ° μ€νμμ€ κ³΅κ° λ°μ΄ν° μλ²
- CVE-2023-25157 β GeoServer OGC νν° SQL μΈμ μ
- Contributor: @djadydwls0720 | Risk Score: 9.8 (Reproducibility: 65%)
- CVE-2023-25157 (2) β GeoServer OGC νν° SQL μΈμ μ
- Contributor: @moooooji | Risk Score: 9.8 (Reproducibility: 60%)
- CVE-2023-25157 β GeoServer OGC νν° SQL μΈμ μ
-
HugeGraph β Apache κΈ°λ° μ€νμμ€ κ·Έλν λ°μ΄ν°λ² μ΄μ€
- CVE-2024-43441 β JWT λΉλ° ν€ νλμ½λ©μΌλ‘ μΈν μΈμ¦ μ°ν
- Contributor: @HanTul | Risk Score: 9.8 (Reproducibility: 85%)
- CVE-2024-43441 β JWT λΉλ° ν€ νλμ½λ©μΌλ‘ μΈν μΈμ¦ μ°ν
-
Librsvg β GNOME SVG λ λλ§ λΌμ΄λΈλ¬λ¦¬
- CVE-2023-38633 β librsvg xi:include λλ ν°λ¦¬ νμ νμΌ μ½κΈ°
- Contributor: @EL55 | Risk Score: 7.5 (Reproducibility: 80%)
- CVE-2023-38633 β librsvg xi:include λλ ν°λ¦¬ νμ νμΌ μ½κΈ°
-
Libssh β SSHv2 νλ‘ν μ½ C λΌμ΄λΈλ¬λ¦¬
- CVE-2018-10933 β libssh μλ² state machine μΈμ¦ μ°ν
- Contributor: @hhtboy | Risk Score: 9.8 (Reproducibility: 75%)
- CVE-2018-10933 β libssh μλ² state machine μΈμ¦ μ°ν
-
MongoExpress β MongoDB μΉ κΈ°λ° κ΄λ¦¬ μΈν°νμ΄μ€
- CVE-2019-10758 β mongo-express μ격 μ½λ μ€ν
- Contributor: @ilohas0021 | Risk Score: 9.8 (Reproducibility: 80%)
- CVE-2019-10758 β mongo-express μ격 μ½λ μ€ν
-
MySQL β κ΄κ³ν λ°μ΄ν°λ² μ΄μ€
- CVE-2012-2122 β MySQL Authentication Bypass
- Contributor: @baethwjd2 | Risk Score: 7.0 (Reproducibility: 70%)
- CVE-2012-2122 β MySQL Authentication Bypass
-
Next.js β React κΈ°λ° νμ€ν μΉ νλ μμν¬
- CVE-2025-29927 β Next.js λ―Έλ€μ¨μ΄ μΈκ° μ°ν
- Contributor: @idealinsane | Risk Score: 9.1 (Reproducibility: 85%)
- CVE-2025-29927 β Next.js λ―Έλ€μ¨μ΄ μΈκ° μ°ν
-
Nginx β κ³ μ±λ₯ μΉ μλ² / 리λ²μ€ νλ‘μ
- CVE-2017-7529 β Nginx Integer Overflow Vulnerability
- Contributor: @c0dep1ayer | Risk Score: 7.5 (Reproducibility: 75%)
- CVE-2017-7529 β Nginx Integer Overflow Vulnerability
-
Node β JavaScript λ°νμ νκ²½
- CVE-2017-14849 β Node.js path.normalize() λλ ν°λ¦¬ νμ μ·¨μ½μ
- Contributor: @ssongk | Risk Score: 7.5 (Reproducibility: 75%)
- CVE-2017-14849 (2) β Node.js path.normalize() λλ ν°λ¦¬ νμ μ·¨μ½μ
- Contributor: @junwonheo | Risk Score: 7.5 (Reproducibility: 65%)
- CVE-2017-14849 β Node.js path.normalize() λλ ν°λ¦¬ νμ μ·¨μ½μ
-
PHP β μλ² μ¬μ΄λ μ€ν¬λ¦½νΈ μΈμ΄
- CVE-2012-1823 β php-cgi μΈμ μ£Όμ
μ ν΅ν μ격 μ½λ μ€ν
- Contributor: @kty121 | Risk Score: 9.8 (Reproducibility: 80%)
- CVE-2012-1823 β php-cgi μΈμ μ£Όμ
μ ν΅ν μ격 μ½λ μ€ν
-
Python β Python λ°νμ νκ²½
- CVE-2017-8291 β PIL(Pillow) GhostScript EPS μ²λ¦¬ RCE
- Contributor: @wjdgnsdl213 | Risk Score: 9.8 (Reproducibility: 75%)
- CVE-2017-8291 β PIL(Pillow) GhostScript EPS μ²λ¦¬ RCE
-
Redis β μΈλ©λͺ¨λ¦¬ ν€-κ° λ°μ΄ν°λ² μ΄μ€
- CVE-2022-0543 β Lua μλλ°μ€ νμΆμ ν΅ν μ격 μ½λ μ€ν
- Contributor: @yeo0n | Risk Score: 10.0 (Reproducibility: 65%)
- CVE-2022-0543 β Lua μλλ°μ€ νμΆμ ν΅ν μ격 μ½λ μ€ν
-
Spring β Java μν°νλΌμ΄μ¦ μΉ νλ μμν¬
- CVE-2022-22963 β Spring Cloud Function SpEL μ½λ μ£Όμ
- Contributor: @foskingson | Risk Score: 9.8 (Reproducibility: 75%)
- CVE-2022-22965 β Spring Framework RCE via Data Binding (Spring4Shell)
- Contributor: @ddddabi | Risk Score: 9.8 (Reproducibility: 70%)
- CVE-2022-22978 β Spring Security Authorization Bypass in RegexRequestMatcher
- Contributor: @sub0810 | Risk Score: 9.8 (Reproducibility: 80%)
- CVE-2022-22963 β Spring Cloud Function SpEL μ½λ μ£Όμ
-
Struts2 β Java κΈ°λ° MVC μΉ νλ μμν¬
- CVE-2018-11776 β Struts2 S2-057 URL λ§€ν OGNL ννμ μ£Όμ
RCE
- Contributor: @ye11oc4t | Risk Score: 8.1 (Reproducibility: 80%)
- CVE-2019-0230 β Struts2 S2-059 OGNL ννμ μ£Όμ
RCE
- Contributor: @hy30nq | Risk Score: 9.8 (Reproducibility: 80%)
- CVE-2018-11776 β Struts2 S2-057 URL λ§€ν OGNL ννμ μ£Όμ
RCE
-
Tiki Wiki β PHP κΈ°λ° μ€νμμ€ CMS / Wiki
- CVE-2020-15906 β TikiWiki CMS Authentication Bypass β RCE
- Contributor: @haijun9 | Risk Score: 8.8 (Reproducibility: 60%)
- CVE-2020-15906 β TikiWiki CMS Authentication Bypass β RCE
-
Tomcat β Java κΈ°λ° μ€νμμ€ μΉ μ ν리μΌμ΄μ μλ²
- CVE-2020-1938 β Apache Tomcat AJP νμΌ μ½κΈ° (Ghostcat)
- Contributor: @mythofsummer | Risk Score: 9.8 (Reproducibility: 70%)
- CVE-2020-1938 β Apache Tomcat AJP νμΌ μ½κΈ° (Ghostcat)
κ° λ³΄κ³ μλ μ·¨μ½μ μ체μ μνλμ Report Reliabilityλ₯Ό λΆλ¦¬ν΄ νκ°ν©λλ€. Docker νκ²½κ³Ό μ μΆλ PoCλ₯Ό μ¬κ²μ¦ν λ€ κΈ°λ‘ν©λλ€.
- Reproducibility: μ μΆλ νκ²½κ³Ό PoCλ₯Ό κ·Έλλ‘ λ°λμ λ μ¬ν κ°λ₯ν μ λλ₯Ό 0%μμ 100%λ‘ ννν©λλ€. νκ²½ ꡬμ±, μ·¨μ½ μ‘°κ±΄, μ¬ν μ μ°¨, PoC μ½λ, μ€ν κ²°κ³Ό, λμ λ°©μμ λͺ νμ±μ κΈ°μ€μΌλ‘ νκ°ν©λλ€.
- Risk Score: μΈμ¦ νμ μ¬λΆ, μ격 μ μ© κ°λ₯μ±, μν₯ λ²μ, PoC λ° Docker νκ²½μμ νμΈλλ μ€μ λμμ κΈ°μ€μΌλ‘ CVSSμ²λΌ 0.0μμ 10.0 μ¬μ΄λ‘ νκ°ν©λλ€.