CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

151 vulnerabilities with CWE-749
CVE-2023-51574 CRITICAL
Voltronic Power ViewPower - Auth Bypass
CVSS 9.8
CVE-2023-44414 CRITICAL
Dlink D-view 8 - Remote Code Execution
CVSS 9.8
CVE-2023-42032 HIGH
Visualware Myconnection Server - Information Disclosure
CVSS 7.5
CVE-2023-40501 CRITICAL
LG Simple Editor - Remote Code Execution
CVSS 9.8
CVE-2023-40500 CRITICAL
LG Simple Editor - Remote Code Execution
CVSS 9.8
CVE-2023-39505 MEDIUM
Pdf-xchange Pdf-tools - Information Disclosure
CVSS 5.5
CVE-2023-39495 MEDIUM
Pdf-xchange Pdf-tools - Information Disclosure
CVSS 5.5
CVE-2023-39493 HIGH
Pdf-xchange Pdf-tools - Remote Code Execution
CVSS 7.8
CVE-2023-39468 HIGH
Trianglemicroworks Scada Data Gateway - Remote Code Execution
CVSS 7.2
CVE-2023-38124 HIGH
Inductiveautomation Ignition < 8.1.26 - Remote Code Execution
CVSS 8.8
CVE-2023-38101 HIGH
Netgear Prosafe Network Management System - Remote Code Execution
CVSS 8.8
CVE-2023-38097 HIGH
Netgear Prosafe Network Management System - Remote Code Execution
CVSS 8.8
CVE-2023-37330 HIGH
Tungstenautomation Power Pdf < 5.0.0.11 - Remote Code Execution
CVSS 7.8
CVE-2023-27365 HIGH
Foxit Pdf Editor < 10.1.11.37866 - Remote Code Execution
CVSS 7.8
CVE-2023-27364 HIGH
Foxit Pdf Editor < 10.1.11.37866 - Remote Code Execution
CVSS 7.8
CVE-2023-27363 HIGH
Foxit Pdf Editor < 10.1.11.37866 - Remote Code Execution
CVSS 7.8
CVE-2023-49074 HIGH
Tp-link Eap225 Firmware - Denial of Service
CVSS 7.4
CVE-2023-51573 CRITICAL
Voltronic Power ViewPower Pro - Auth Bypass
CVSS 9.8
CVE-2023-5389 CRITICAL
Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC - Fil...
CVSS 9.1
CVE-2023-50424 CRITICAL
SAP BTP Security Services Integration Library < 0.17.0 - Privilege Escalation
CVSS 9.1
CVE-2023-50423 CRITICAL
Sap-xssec < 4.1.0 - XSS
CVSS 9.1
CVE-2023-50422 CRITICAL
SAP BTP Security Services Integration Library <2.17.0 and 3.0.0-<3.3.0 - Privilege Escalation
CVSS 9.1
CVE-2023-49583 CRITICAL
@sap/xssec < 3.6.0 - XSS
CVSS 9.1
CVE-2023-39226 CRITICAL
Delta Electronics InfraSuite Device Master <1.0.7 - RCE
CVSS 9.8
CVE-2023-40151 CRITICAL
Red Lion SixTRAK and VersaTRAK Series - Privilege Escalation
CVSS 10.0
Details
Vulnerabilities 151
Exploit Likelihood Low