CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

178 vulnerabilities with CWE-749
CVE-2024-55922 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 5.4
CVE-2024-55921 HIGH
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery and Remote Code Execution via Extension Manager Module
CVSS 7.5
CVE-2024-55920 MEDIUM
TYPO3 10.0.0-10.4.48 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55894 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-55893 MEDIUM
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
CVE-2024-13242 CRITICAL
Drupal Swift Mailer - Resource Location Spoofing via Exposed Dangerous Method
CVSS 9.1
CVE-2024-51992 MEDIUM
Orchid Platform 8.0-14.42.x - Exposed Dangerous Method in Asynchronous Modal Functionality
CVSS 4.1
CVE-2024-47005 HIGH
Sharp/Toshiba Tec MFP - Info Disclosure
CVSS 8.1
CVE-2024-4739 MEDIUM
MXsecurity <v1.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-6510 HIGH
AVG Internet Security <24 - Privilege Escalation
CVSS 7.8
CVE-2024-6689 HIGH
baramundi Management Agent <23.1.172.0 - Privilege Escalation
CVSS 7.8
CVE-2024-35209 MEDIUM
SINEC Traffic Analyzer <V1.2 - Info Disclosure
CVSS 6.2
CVE-2024-5299 HIGH
D-Link D-View 8 - Remote Code Execution via execMonitorScript Method
CVSS 8.8
CVE-2024-5298 HIGH
D-Link D-View 8 - Remote Code Execution via queryDeviceCustomMonitorResult Method
CVSS 8.8
CVE-2024-32764 CRITICAL
myQNAPcloud Link <2.4.51 - Privilege Escalation
CVSS 9.9
CVE-2024-27261 MEDIUM
IBM Storage Defender - Resiliency Service <2.0.3 - Privilege Escala...
CVSS 6.4
CVE-2024-29880 MEDIUM
JetBrains TeamCity <2023.11 - Privilege Escalation
CVSS 4.2
CVE-2024-27444 CRITICAL
langchain-experimental < 0.1.8 - Remote Code Execution via Unrestricted Python Attribute Access
CVSS 9.8
CVE-2024-25675 CRITICAL
MISP < 2.4.184 - Unauthenticated Export Generation via GET Request
CVSS 9.8
CVE-2023-39470 HIGH
PaperCut NG < 22.1.1 - Authenticated Remote Code Execution via Exposed Dangerous Function
CVSS 7.2
CVE-2023-51584 HIGH
Voltronic Power ViewPower Pro - Remote Code Execution via Exposed Shutdown Method
CVSS 8.8
CVE-2023-51583 CRITICAL
Voltronic Power ViewPower - Unauthenticated Remote Code Execution via UpsScheduler Exposed Method
CVSS 9.8
CVE-2023-51582 CRITICAL
Voltronic Power ViewPower - Unauthenticated Remote Code Execution via LinuxMonitorConsole
CVSS 9.8
CVE-2023-51581 CRITICAL
Voltronic Power ViewPower - Remote Code Execution via MacMonitorConsole Exposed Method
CVSS 9.8
CVE-2023-51578 HIGH
Voltronic Power ViewPower - Unauthenticated Denial of Service via MonitorConsole Exposed Method
CVSS 7.5
Details
Vulnerabilities 178
Exploit Likelihood Low