CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

151 vulnerabilities with CWE-749
CVE-2026-5173 HIGH
Exposed Dangerous Method or Function in GitLab
CVSS 8.5
CVE-2026-35488 HIGH
Tandoor Recipes — CustomIsShared permits DELETE/PUT on RecipeBook by shared (read-only) users
CVSS 8.1
CVE-2026-2275 CRITICAL
CrewAI 1.0 - RCE via CodeInterpreter Sandbox Fallback
CVSS 9.6
CVE-2026-3483 HIGH
Ivanti DSM <2026.1.1 - Privilege Escalation
CVSS 7.8
CVE-2026-30957 CRITICAL
OneUptime <10.0.21 - Command Injection
CVSS 9.9
CVE-2026-30921 CRITICAL
OneUptime <10.0.20 - RCE
CVSS 9.9
CVE-2026-30797 HIGH
RustDesk Client <=1.4.5 - Auth Bypass
CVSS 8.1
CVE-2026-20423 HIGH
wlan STA driver - Privilege Escalation
CVSS 7.8
CVE-2026-28400 HIGH
Docker Model Runner <1.0.16 - Command Injection
CVSS 7.5
CVE-2026-22208 CRITICAL
OpenS100 <753cf29 - RCE
CVSS 9.6
CVE-2026-22812 HIGH
OpenCode <1.0.216 - Command Injection
CVSS 8.8
CVE-2025-47366 HIGH
Qualcomm FastConnect and AR8035 Firmware - Cryptographic Issue in Trusted Zone
CVSS 7.1
CVE-2025-9611 HIGH
Microsoft Playwright MCP Server <0.0.40 - SSRF
CVE-2025-68697 HIGH
n8n <2.0.0 - Privilege Escalation
CVSS 7.1
CVE-2025-14497 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14496 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14495 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14494 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14493 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14492 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14491 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14490 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14489 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14488 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-59788 MEDIUM
Nextcloud <32.0.1 - XSS
CVSS 6.4
Details
Vulnerabilities 151
Exploit Likelihood Low