CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
178 vulnerabilities with CWE-749
CVE-2026-44107
HIGH
Phoenix Contact CHARX SEC-3150 - Exposed Reboot via Modbus
CVSS 7.5
CVE-2026-45805
HIGH
Penpot < 2.15.0 MCP REPL - Unauthenticated Remote Code Execution
CVSS 8.8
CVE-2026-53633
CRITICAL
Vitest Browser Mode - Remote Code Execution via Exposed CDP API
CVSS 9.8
CVE-2026-45489
MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVSS 6.5
CVE-2026-14620
MEDIUM
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
CVSS 4.7
CVE-2026-54753
MEDIUM
Nx: `nx graph` dev server permissive CORS policy
CVSS 5.9
CVE-2026-55454
CRITICAL
Appsmith: Caddy admin API exposed without authentication
CVSS 9.9
CVE-2026-48783
MEDIUM
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
CVSS 4.8
CVE-2026-49993
MEDIUM
Nuxt Builders >=3.15.4,<3.21.7 and >=4.0.0,<4.4.7 - Source Code Disclosure
CVSS 5.7
CVE-2026-45670
MEDIUM
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
CVSS 5.4
CVE-2026-12060
MEDIUM
Hepta Platforms|Heptabase - Exposed Dangerous
CVSS 6.5
CVE-2026-7516
MEDIUM
Lenovo Application < 7.3.8 - Exposed Dangerous Method or Function
CVSS 4.3
CVE-2026-47899
HIGH
Arbitrary File Read, Write, Rename, and Delete in Logseq
CVE-2026-41283
CRITICAL
Openstack Mistral - Incorrect Authorization
CVSS 9.9
CVE-2026-44698
HIGH
Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
CVSS 8.3
CVE-2026-44798
HIGH
Nautobot: GitRepository.current_head field should not be writable through REST API
CVSS 7.1
CVE-2026-44836
MEDIUM
view_component: Preview Route Can Dispatch Inherited Helper Methods
CVSS 6.5
CVE-2026-4051
HIGH
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution
CVSS 7.2
CVE-2026-33584
MEDIUM
Arqit SKA-Platform Enables Access to Debug Information
CVSS 5.3
CVE-2026-33583
HIGH
Arqit SKA-Platform Vulnerable to Key Exposure
CVSS 8.7
CVE-2026-8108
HIGH
Fuji Electric Tellus Exposed Dangerous Method or Function
CVSS 7.8
CVE-2026-8109
MEDIUM
Ivanti Endpoint Manager < 2024 SU6 - Authenticated Credential Leak via Exposed Core Server Method
CVSS 6.5
CVE-2026-6402
MEDIUM
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVSS 5.3
CVE-2026-25266
MEDIUM
Exposed dangerous function in windows host
CVSS 5.5
CVE-2026-24118
CRITICAL
VM2 Sandbox Breakout Through __lookupGetter__
CVSS 9.8
Details
Vulnerabilities
178
Exploit Likelihood
Low