CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

151 vulnerabilities with CWE-749
CVE-2025-64443 CRITICAL
MCP Gateway <0.27.0 - SSRF
CVSS 9.6
CVE-2025-47353 HIGH
GVM - Memory Corruption
CVSS 7.8
CVE-2025-61907 MEDIUM
Icinga < 2.13.13 - Information Disclosure
CVSS 6.5
CVE-2025-59403 CRITICAL
Flocksafety Flock Safety - Remote Code Execution
CVSS 9.8
CVE-2025-34114 HIGH
OpenBlow - XSS
CVE-2025-53964 CRITICAL
GoldenDict <1.5.2 - Info Disclosure
CVSS 9.6
CVE-2025-37097 HIGH
HPE Insight Remote Support < 7.15.0.646 - Denial of Service
CVSS 7.5
CVE-2025-5823 MEDIUM
Autel MaxiCharger AC Wallbox Commercial - Info Disclosure
CVSS 6.5
CVE-2025-5748 HIGH
Wolfbox Level 2 EV Charger Firmware - Remote Code Execution
CVSS 8.0
CVE-2025-30359 MEDIUM
webpack-dev-server <5.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-48415 MEDIUM
USB Device - RCE
CVSS 6.2
CVE-2025-43003 MEDIUM
SAP S/4 HANA - Privilege Escalation
CVSS 6.4
CVE-2025-43955 LOW
Convertigo <8.3.4 - Code Injection
CVSS 2.2
CVE-2025-3698 HIGH
Tecno Carlcare - Information Disclosure
CVSS 7.5
CVE-2025-26651 MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-24361 MEDIUM
Nuxt <3.15.12 - Info Disclosure
CVSS 5.3
CVE-2025-24359 HIGH
ASTEVAL <1.0.6 - Code Injection
CVSS 8.4
CVE-2024-43065 HIGH
RKP - Info Disclosure
CVSS 7.1
CVE-2024-6863 MEDIUM
h2o-3 <3.46.0 - Code Injection
CVSS 6.5
CVE-2024-12651 HIGH
PTT Inc. HGS Mobile App <6.5.0 - Code Injection
CVSS 8.5
CVE-2024-55945 MEDIUM
Typo3 < 11.5.42 - CSRF
CVSS 4.3
CVE-2024-55924 HIGH
Typo3 < 11.5.42 - CSRF
CVSS 8.0
CVE-2024-55923 MEDIUM
Typo3 < 10.4.48 - CSRF
CVSS 4.3
CVE-2024-55922 MEDIUM
Typo3 < 10.4.48 - CSRF
CVSS 5.4
CVE-2024-55921 HIGH
Typo3 < 10.4.48 - Remote Code Execution
CVSS 7.5
Details
Vulnerabilities 151
Exploit Likelihood Low