CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
178 vulnerabilities with CWE-749
CVE-2024-55922
MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 5.4
CVE-2024-55921
HIGH
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery and Remote Code Execution via Extension Manager Module
CVSS 7.5
CVE-2024-55920
MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55894
MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55893
MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-13242
CRITICAL
Drupal Swift Mailer - Resource Location Spoofing via Exposed Dangerous Method
CVSS 9.1
CVE-2024-51992
MEDIUM
Orchid Platform 8.0-14.42.x - Exposed Dangerous Method in Asynchronous Modal Functionality
CVSS 4.1
CVE-2024-47005
HIGH
Sharp/Toshiba Tec MFP - Info Disclosure
CVSS 8.1
CVE-2024-4739
MEDIUM
MXsecurity <v1.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-6510
HIGH
AVG Internet Security <24 - Privilege Escalation
CVSS 7.8
CVE-2024-6689
HIGH
baramundi Management Agent <23.1.172.0 - Privilege Escalation
CVSS 7.8
CVE-2024-35209
MEDIUM
SINEC Traffic Analyzer <V1.2 - Info Disclosure
CVSS 6.2
CVE-2024-5299
HIGH
D-Link D-View 8 - Remote Code Execution via execMonitorScript Method
CVSS 8.8
CVE-2024-5298
HIGH
D-Link D-View 8 - Remote Code Execution via queryDeviceCustomMonitorResult Method
CVSS 8.8
CVE-2024-32764
CRITICAL
myQNAPcloud Link <2.4.51 - Privilege Escalation
CVSS 9.9
CVE-2024-27261
MEDIUM
IBM Storage Defender - Resiliency Service <2.0.3 - Privilege Escala...
CVSS 6.4
CVE-2024-29880
MEDIUM
JetBrains TeamCity <2023.11 - Privilege Escalation
CVSS 4.2
CVE-2024-27444
CRITICAL
langchain-experimental < 0.1.8 - Remote Code Execution via Unrestricted Python Attribute Access
CVSS 9.8
CVE-2024-25675
CRITICAL
MISP < 2.4.184 - Unauthenticated Export Generation via GET Request
CVSS 9.8
CVE-2023-39470
HIGH
PaperCut NG < 22.1.1 - Authenticated Remote Code Execution via Exposed Dangerous Function
CVSS 7.2
CVE-2023-51584
HIGH
Voltronic Power ViewPower Pro - Remote Code Execution via Exposed Shutdown Method
CVSS 8.8
CVE-2023-51583
CRITICAL
Voltronic Power ViewPower - Unauthenticated Remote Code Execution via UpsScheduler Exposed Method
CVSS 9.8
CVE-2023-51582
CRITICAL
Voltronic Power ViewPower - Unauthenticated Remote Code Execution via LinuxMonitorConsole
CVSS 9.8
CVE-2023-51581
CRITICAL
Voltronic Power ViewPower - Remote Code Execution via MacMonitorConsole Exposed Method
CVSS 9.8
CVE-2023-51578
HIGH
Voltronic Power ViewPower - Unauthenticated Denial of Service via MonitorConsole Exposed Method
CVSS 7.5
Details
Vulnerabilities
178
Exploit Likelihood
Low