CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

151 vulnerabilities with CWE-749
CVE-2023-42494 HIGH
EisBaer Scada - Buffer Overflow
CVSS 7.5
CVE-2023-3656 CRITICAL
Cashit! - Remote Code Execution
CVSS 9.8
CVE-2023-3655 HIGH
cashIT! - PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH 03.A06rk...
CVSS 7.5
CVE-2023-40150 CRITICAL
Softneta Meddream Pacs < 7.2.8.810 - Remote Code Execution
CVSS 9.8
CVE-2023-3612 HIGH
Govee Home - SSRF
CVSS 8.2
CVE-2023-39214 HIGH
Zoom Client SDK <5.15.5 - Info Disclosure
CVSS 7.6
CVE-2023-36853 HIGH
Keysight Geolocation Server <v2.4.2 - Code Injection
CVSS 7.8
CVE-2023-33921 MEDIUM
CP-8031/CP-8050 <CPCI85 V05 - Info Disclosure
CVSS 6.8
CVE-2023-34227 MEDIUM
JetBrains TeamCity <2023.05 - DoS
CVSS 5.3
CVE-2023-26478 MEDIUM
XWiki Platform <14.3-rc-1 - Info Disclosure
CVSS 6.6
CVE-2022-31491 CRITICAL
Voltronic Power ViewPower <1.04-24215, ViewPower Pro <2.0-22165, Po...
CVSS 10.0
CVE-2022-37365 HIGH
PDF-XChange Editor - RCE
CVSS 7.8
CVE-2022-46156 HIGH
Grafana Synthetic Monitoring <0.12.0 - Info Disclosure
CVSS 7.2
CVE-2022-4136 CRITICAL
qmpass/leadshop <1.4.15 - RCE
CVSS 9.8
CVE-2021-33639 HIGH
SVM Driver - Memory Corruption
CVSS 7.5
CVE-2021-34996 HIGH
Commvault CommCell 11.22.22 - RCE
CVSS 8.8
CVE-2021-35243 MEDIUM
Web Help Desk <12.7.7 - Info Disclosure
CVSS 5.3
CVE-2021-42128 CRITICAL
Ivanti Avalanche < 6.3.3 - Privilege Escalation
CVSS 9.8
CVE-2021-26614 HIGH
Iptime C200 Firmware < 1.060 - Remote Code Execution
CVSS 7.5
CVE-2021-28809 CRITICAL
HBS 3 - Improper Access Control
CVSS 9.8
CVE-2020-2503 CRITICAL
Qnap Qes < 2.1.1 - Basic XSS
CVSS 9.0
CVE-2020-12927 HIGH
AMD VBIOS Flash Tool SDK - Privilege Escalation
CVSS 7.8
CVE-2020-12912 MEDIUM
AMD hwmon - Privilege Escalation
CVSS 5.5
CVE-2020-27123 MEDIUM
Cisco AnyConnect Secure Mobility Client for Windows - Info Disclosure
CVSS 5.5
CVE-2020-12928 HIGH
AMD Ryzen Master V15 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 151
Exploit Likelihood Low