CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
167 vulnerabilities with CWE-749
CVE-2026-22812
HIGH
OpenCode <1.0.216 - Command Injection
CVSS 8.8
CVE-2025-14713
HIGH
Synology C2 Identity Edge Server < 1.76.0-0307 - Exposed Dangerous Method or Function
CVSS 7.5
CVE-2025-47366
HIGH
Qualcomm FastConnect and AR8035 Firmware - Cryptographic Issue in Trusted Zone
CVSS 7.1
CVE-2025-9611
HIGH
Microsoft Playwright MCP Server <0.0.40 - SSRF
CVE-2025-68697
HIGH
n8n < 2.0.0 - Authenticated Arbitrary File Read and Write via Code Node Helper Functions
CVSS 7.1
CVE-2025-14497
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14496
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14495
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14494
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14493
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14492
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14491
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14490
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14489
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-14488
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-59788
MEDIUM
Nextcloud < 32.0.1 - Cross-Site Scripting via Crafted PDF File
CVSS 6.4
CVE-2025-64443
CRITICAL
docker/mcp-gateway < 0.28.0 - DNS Rebinding in SSE or Streaming Transport Mode
CVSS 9.6
CVE-2025-47353
HIGH
Qualcomm Firmware - Memory Corruption via GVM Request Processing
CVSS 7.8
CVE-2025-61907
MEDIUM
Icinga 2.4-2.15.0 - Authenticated Information Disclosure via Filter Expression
CVSS 6.5
CVE-2025-59403
CRITICAL
Flock Safety Android Collins 6.35.31 - RCE & DoS via Exposed API
CVSS 9.8
CVE-2025-34114
HIGH
OpenBlow - Client-Side Security Misconfiguration via Missing Critical HTTP Response Headers
CVE-2025-53964
CRITICAL
GoldenDict <1.5.2 - Info Disclosure
CVSS 9.6
CVE-2025-37097
HIGH
HPE Insight Remote Support < 7.15.0.646 - Unauthenticated Denial of Service
CVSS 7.5
CVE-2025-5823
MEDIUM
Autel MaxiCharger AC Wallbox Commercial - Info Disclosure
CVSS 6.5
CVE-2025-5748
HIGH
WOLFBOX Level 2 EV Charger Firmware - Remote Code Execution via Tuya Communications Module
CVSS 8.0
Details
Vulnerabilities
167
Exploit Likelihood
Low