CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

178 vulnerabilities with CWE-749
CVE-2025-14488 HIGH
RealDefense SUPERAntiSpyware - Privilege Escalation
CVSS 7.8
CVE-2025-59788 MEDIUM
Nextcloud < 32.0.1 - Cross-Site Scripting via Crafted PDF File
CVSS 6.4
CVE-2025-64443 CRITICAL
docker/mcp-gateway < 0.28.0 - DNS Rebinding in SSE or Streaming Transport Mode
CVSS 9.6
CVE-2025-47353 HIGH
Qualcomm Firmware - Memory Corruption via GVM Request Processing
CVSS 7.8
CVE-2025-61907 MEDIUM
Icinga 2.4-2.15.0 - Authenticated Information Disclosure via Filter Expression
CVSS 6.5
CVE-2025-59403 CRITICAL
Flock Safety Android Collins 6.35.31 - RCE & DoS via Exposed API
CVSS 9.8
CVE-2025-34114 HIGH
OpenBlow - Client-Side Security Misconfiguration via Missing Critical HTTP Response Headers
CVE-2025-53964 CRITICAL
GoldenDict <1.5.2 - Info Disclosure
CVSS 9.6
CVE-2025-37097 HIGH
HPE Insight Remote Support < 7.15.0.646 - Unauthenticated Denial of Service
CVSS 7.5
CVE-2025-5823 MEDIUM
Autel MaxiCharger AC Wallbox Commercial - Info Disclosure
CVSS 6.5
CVE-2025-5748 HIGH
WOLFBOX Level 2 EV Charger Firmware - Remote Code Execution via Tuya Communications Module
CVSS 8.0
CVE-2025-30359 MEDIUM
webpack-dev-server <5.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-48415 MEDIUM
eCharge cPH2 and cPP2 Charging Stations <=2.2.0 - USB Backdoor Command Execution
CVSS 6.2
CVE-2025-43003 MEDIUM
SAP S/4 HANA - Privilege Escalation
CVSS 6.4
CVE-2025-43955 LOW
Convertigo < 8.3.4 - Exposed Dangerous Method via TwsCachedXPathAPI
CVSS 2.2
CVE-2025-3698 HIGH
Carlcare - Information Exposure via Interface Exposure
CVSS 7.5
CVE-2025-26651 MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-24361 MEDIUM
Nuxt 3.0.0-3.15.12 - Source Code Exposure via Webpack Chunk Inspection
CVSS 5.3
CVE-2025-24359 HIGH
asteval < 1.0.6 - Remote Code Execution via FormattedValue AST Node Handling
CVSS 8.4
CVE-2024-43065 HIGH
Qualcomm FastConnect 7800 Firmware - Cryptographic Key Pair Generation Issue
CVSS 7.1
CVE-2024-6863 MEDIUM
h2oai/h2o-3 3.46.0 - Arbitrary File Encryption via EncryptionTool Endpoint
CVSS 6.5
CVE-2024-12651 HIGH
PTT Inc. HGS Mobile App <6.5.0 - Code Injection
CVSS 8.5
CVE-2024-55945 MEDIUM
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55924 HIGH
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 8.0
CVE-2024-55923 MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
Details
Vulnerabilities 178
Exploit Likelihood Low