CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

167 vulnerabilities with CWE-749
CVE-2025-30359 MEDIUM
webpack-dev-server <5.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-48415 MEDIUM
eCharge cPH2 and cPP2 Charging Stations <=2.2.0 - USB Backdoor Command Execution
CVSS 6.2
CVE-2025-43003 MEDIUM
SAP S/4 HANA - Privilege Escalation
CVSS 6.4
CVE-2025-43955 LOW
Convertigo < 8.3.4 - Exposed Dangerous Method via TwsCachedXPathAPI
CVSS 2.2
CVE-2025-3698 HIGH
Carlcare - Information Exposure via Interface Exposure
CVSS 7.5
CVE-2025-26651 MEDIUM
Windows Local Session Manager - DoS
CVSS 6.5
CVE-2025-24361 MEDIUM
Nuxt 3.0.0-3.15.12 - Source Code Exposure via Webpack Chunk Inspection
CVSS 5.3
CVE-2025-24359 HIGH
asteval < 1.0.6 - Remote Code Execution via FormattedValue AST Node Handling
CVSS 8.4
CVE-2024-43065 HIGH
Qualcomm FastConnect 7800 Firmware - Cryptographic Key Pair Generation Issue
CVSS 7.1
CVE-2024-6863 MEDIUM
h2oai/h2o-3 3.46.0 - Arbitrary File Encryption via EncryptionTool Endpoint
CVSS 6.5
CVE-2024-12651 HIGH
PTT Inc. HGS Mobile App <6.5.0 - Code Injection
CVSS 8.5
CVE-2024-55945 MEDIUM
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55924 HIGH
TYPO3 11.0.0-11.5.41 - Cross-Site Request Forgery via Backend Deep Links
CVSS 8.0
CVE-2024-55923 MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55922 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 5.4
CVE-2024-55921 HIGH
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery and Remote Code Execution via Extension Manager Module
CVSS 7.5
CVE-2024-55920 MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55894 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55893 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-13242 CRITICAL
Drupal Swift Mailer - Resource Location Spoofing via Exposed Dangerous Method
CVSS 9.1
CVE-2024-51992 MEDIUM
Orchid Platform 8.0-14.42.x - Exposed Dangerous Method in Asynchronous Modal Functionality
CVSS 4.1
CVE-2024-47005 HIGH
Sharp/Toshiba Tec MFP - Info Disclosure
CVSS 8.1
CVE-2024-4739 MEDIUM
MXsecurity <v1.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-6510 HIGH
AVG Internet Security <24 - Privilege Escalation
CVSS 7.8
CVE-2024-6689 HIGH
baramundi Management Agent <23.1.172.0 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 167
Exploit Likelihood Low