CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

178 vulnerabilities with CWE-749
CVE-2026-44107 HIGH
Phoenix Contact CHARX SEC-3150 - Exposed Reboot via Modbus
CVSS 7.5
CVE-2026-45805 HIGH
Penpot < 2.15.0 MCP REPL - Unauthenticated Remote Code Execution
CVSS 8.8
CVE-2026-53633 CRITICAL
Vitest Browser Mode - Remote Code Execution via Exposed CDP API
CVSS 9.8
CVE-2026-45489 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVSS 6.5
CVE-2026-14620 MEDIUM
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
CVSS 4.7
CVE-2026-54753 MEDIUM
Nx: `nx graph` dev server permissive CORS policy
CVSS 5.9
CVE-2026-55454 CRITICAL
Appsmith: Caddy admin API exposed without authentication
CVSS 9.9
CVE-2026-48783 MEDIUM
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
CVSS 4.8
CVE-2026-49993 MEDIUM
Nuxt Builders >=3.15.4,<3.21.7 and >=4.0.0,<4.4.7 - Source Code Disclosure
CVSS 5.7
CVE-2026-45670 MEDIUM
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
CVSS 5.4
CVE-2026-12060 MEDIUM
Hepta Platforms|Heptabase - Exposed Dangerous
CVSS 6.5
CVE-2026-7516 MEDIUM
Lenovo Application < 7.3.8 - Exposed Dangerous Method or Function
CVSS 4.3
CVE-2026-47899 HIGH
Arbitrary File Read, Write, Rename, and Delete in Logseq
CVE-2026-41283 CRITICAL
Openstack Mistral - Incorrect Authorization
CVSS 9.9
CVE-2026-44698 HIGH
Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
CVSS 8.3
CVE-2026-44798 HIGH
Nautobot: GitRepository.current_head field should not be writable through REST API
CVSS 7.1
CVE-2026-44836 MEDIUM
view_component: Preview Route Can Dispatch Inherited Helper Methods
CVSS 6.5
CVE-2026-4051 HIGH
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution
CVSS 7.2
CVE-2026-33584 MEDIUM
Arqit SKA-Platform Enables Access to Debug Information
CVSS 5.3
CVE-2026-33583 HIGH
Arqit SKA-Platform Vulnerable to Key Exposure
CVSS 8.7
CVE-2026-8108 HIGH
Fuji Electric Tellus Exposed Dangerous Method or Function
CVSS 7.8
CVE-2026-8109 MEDIUM
Ivanti Endpoint Manager < 2024 SU6 - Authenticated Credential Leak via Exposed Core Server Method
CVSS 6.5
CVE-2026-6402 MEDIUM
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVSS 5.3
CVE-2026-25266 MEDIUM
Exposed dangerous function in windows host
CVSS 5.5
CVE-2026-24118 CRITICAL
VM2 Sandbox Breakout Through __lookupGetter__
CVSS 9.8
Details
Vulnerabilities 178
Exploit Likelihood Low