CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

167 vulnerabilities with CWE-749
CVE-2026-49993 MEDIUM
Nuxt Builders >=3.15.4,<3.21.7 and >=4.0.0,<4.4.7 - Source Code Disclosure
CVSS 5.7
CVE-2026-45670 MEDIUM
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
CVSS 5.4
CVE-2026-12060 MEDIUM
Hepta Platforms|Heptabase - Exposed Dangerous
CVSS 6.5
CVE-2026-7516 MEDIUM
Lenovo Application < 7.3.8 - Exposed Dangerous Method or Function
CVSS 4.3
CVE-2026-47899 HIGH
Arbitrary File Read, Write, Rename, and Delete in Logseq
CVE-2026-44698 HIGH
Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
CVSS 8.3
CVE-2026-44798 HIGH
Nautobot: GitRepository.current_head field should not be writable through REST API
CVSS 7.1
CVE-2026-44836 MEDIUM
view_component: Preview Route Can Dispatch Inherited Helper Methods
CVSS 6.5
CVE-2026-4051 HIGH
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution
CVSS 7.2
CVE-2026-33584 MEDIUM
Arqit SKA-Platform Enables Access to Debug Information
CVSS 5.3
CVE-2026-33583 HIGH
Arqit SKA-Platform Vulnerable to Key Exposure
CVSS 8.7
CVE-2026-8108 HIGH
Fuji Electric Tellus Exposed Dangerous Method or Function
CVSS 7.8
CVE-2026-8109 MEDIUM
Ivanti Endpoint Manager < 2024 SU6 - Authenticated Credential Leak via Exposed Core Server Method
CVSS 6.5
CVE-2026-6402 MEDIUM
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVSS 5.3
CVE-2026-25266 MEDIUM
Exposed dangerous function in windows host
CVSS 5.5
CVE-2026-5173 HIGH
Exposed Dangerous Method or Function in GitLab
CVSS 8.5
CVE-2026-35488 HIGH
Tandoor Recipes — CustomIsShared permits DELETE/PUT on RecipeBook by shared (read-only) users
CVSS 8.1
CVE-2026-2275 CRITICAL
CrewAI 1.0 - RCE via CodeInterpreter Sandbox Fallback
CVSS 9.6
CVE-2026-3483 HIGH
Ivanti DSM <2026.1.1 - Privilege Escalation
CVSS 7.8
CVE-2026-30957 CRITICAL
OneUptime <10.0.21 - Command Injection
CVSS 9.9
CVE-2026-30921 CRITICAL
OneUptime < 10.0.20 - Synthetic Monitor Remote Code Execution
CVSS 9.9
CVE-2026-30797 HIGH
RustDesk Client <=1.4.5 - Auth Bypass
CVSS 8.1
CVE-2026-20423 HIGH
wlan STA driver - Privilege Escalation
CVSS 7.8
CVE-2026-28400 HIGH
Docker Model Runner <1.0.16 - Command Injection
CVSS 7.5
CVE-2026-22208 CRITICAL
OpenS100 < 753cf29 - Remote Code Execution via Unrestricted Lua Standard Library Access
CVSS 9.6
Details
Vulnerabilities 167
Exploit Likelihood Low