CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
178 vulnerabilities with CWE-749
CVE-2025-14488
HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-59788
MEDIUM
Nextcloud < 32.0.1 - Cross-Site Scripting via Crafted PDF File
CVSS 6.4
CVE-2025-64443
CRITICAL
docker/mcp-gateway < 0.28.0 - DNS Rebinding in SSE or Streaming Transport Mode
CVSS 9.6
CVE-2025-47353
HIGH
Qualcomm Firmware - Memory Corruption via GVM Request Processing
CVSS 7.8
CVE-2025-61907
MEDIUM
Icinga 2.4-2.15.0 - Authenticated Information Disclosure via Filter Expression
CVSS 6.5
CVE-2025-59403
CRITICAL
Flock Safety Android Collins 6.35.31 - RCE & DoS via Exposed API
CVSS 9.8
CVE-2025-34114
HIGH
OpenBlow - Client-Side Security Misconfiguration via Missing Critical HTTP Response Headers
CVE-2025-53964
CRITICAL
GoldenDict <1.5.2 - Info Disclosure
CVSS 9.6
CVE-2025-37097
HIGH
HPE Insight Remote Support < 7.15.0.646 - Unauthenticated Denial of Service
CVSS 7.5
CVE-2025-5823
MEDIUM
Autel MaxiCharger AC Wallbox Commercial - Info Disclosure
CVSS 6.5
CVE-2025-5748
HIGH
WOLFBOX Level 2 EV Charger Firmware - Remote Code Execution via Tuya Communications Module
CVSS 8.0
CVE-2025-30359
MEDIUM
webpack-dev-server <5.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-48415
MEDIUM
eCharge cPH2 and cPP2 Charging Stations <=2.2.0 - USB Backdoor Command Execution
CVSS 6.2
CVE-2025-43003
MEDIUM
SAP S/4 HANA - Privilege Escalation
CVSS 6.4
CVE-2025-43955
LOW
Convertigo < 8.3.4 - Exposed Dangerous Method via TwsCachedXPathAPI
CVSS 2.2
CVE-2025-3698
HIGH
Carlcare - Information Exposure via Interface Exposure
CVSS 7.5
CVE-2025-26651
MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-24361
MEDIUM
Nuxt 3.0.0-3.15.12 - Source Code Exposure via Webpack Chunk Inspection
CVSS 5.3
CVE-2025-24359
HIGH
asteval < 1.0.6 - Remote Code Execution via FormattedValue AST Node Handling
CVSS 8.4
CVE-2024-43065
HIGH
Qualcomm FastConnect 7800 Firmware - Cryptographic Key Pair Generation Issue
CVSS 7.1
CVE-2024-6863
MEDIUM
h2oai/h2o-3 3.46.0 - Arbitrary File Encryption via EncryptionTool Endpoint
CVSS 6.5
CVE-2024-12651
HIGH
PTT Inc. HGS Mobile App <6.5.0 - Code Injection
CVSS 8.5
CVE-2024-55945
MEDIUM
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55924
HIGH
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 8.0
CVE-2024-55923
MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
Details
Vulnerabilities
178
Exploit Likelihood
Low