CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
167 vulnerabilities with CWE-749
CVE-2025-30359
MEDIUM
webpack-dev-server <5.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-48415
MEDIUM
eCharge cPH2 and cPP2 Charging Stations <=2.2.0 - USB Backdoor Command Execution
CVSS 6.2
CVE-2025-43003
MEDIUM
SAP S/4 HANA - Privilege Escalation
CVSS 6.4
CVE-2025-43955
LOW
Convertigo < 8.3.4 - Exposed Dangerous Method via TwsCachedXPathAPI
CVSS 2.2
CVE-2025-3698
HIGH
Carlcare - Information Exposure via Interface Exposure
CVSS 7.5
CVE-2025-26651
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-24361
MEDIUM
Nuxt 3.0.0-3.15.12 - Source Code Exposure via Webpack Chunk Inspection
CVSS 5.3
CVE-2025-24359
HIGH
asteval < 1.0.6 - Remote Code Execution via FormattedValue AST Node Handling
CVSS 8.4
CVE-2024-43065
HIGH
Qualcomm FastConnect 7800 Firmware - Cryptographic Key Pair Generation Issue
CVSS 7.1
CVE-2024-6863
MEDIUM
h2oai/h2o-3 3.46.0 - Arbitrary File Encryption via EncryptionTool Endpoint
CVSS 6.5
CVE-2024-12651
HIGH
PTT Inc. HGS Mobile App <6.5.0 - Code Injection
CVSS 8.5
CVE-2024-55945
MEDIUM
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55924
HIGH
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 8.0
CVE-2024-55923
MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55922
MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 5.4
CVE-2024-55921
HIGH
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery and Remote Code Execution via Extension Manager Module
CVSS 7.5
CVE-2024-55920
MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55894
MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55893
MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-13242
CRITICAL
Drupal Swift Mailer - Resource Location Spoofing via Exposed Dangerous Method
CVSS 9.1
CVE-2024-51992
MEDIUM
Orchid Platform 8.0-14.42.x - Exposed Dangerous Method in Asynchronous Modal Functionality
CVSS 4.1
CVE-2024-47005
HIGH
Sharp/Toshiba Tec MFP - Info Disclosure
CVSS 8.1
CVE-2024-4739
MEDIUM
MXsecurity <v1.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-6510
HIGH
AVG Internet Security <24 - Privilege Escalation
CVSS 7.8
CVE-2024-6689
HIGH
baramundi Management Agent <23.1.172.0 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
167
Exploit Likelihood
Low