CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
167 vulnerabilities with CWE-749
CVE-2023-38124
HIGH
Inductive Automation Ignition < 8.1.26 - Authenticated Remote Code Execution via OPC UA Quick Client Task Scheduling
CVSS 8.8
CVE-2023-38101
HIGH
NETGEAR ProSAFE Network Management System < 1.7.0.20 - Remote Code Execution via SettingConfigController
CVSS 8.8
CVE-2023-38097
HIGH
NETGEAR ProSAFE Network Management System < 1.7.0.20 - Remote Code Execution via BkreProcessThread Exposed Function
CVSS 8.8
CVE-2023-37330
HIGH
Kofax Power PDF < 5.0.0.11 - Remote Code Execution via exportAsText Method
CVSS 7.8
CVE-2023-27365
HIGH
Foxit PDF Editor - Remote Code Execution via DOC File Macro Parsing
CVSS 7.8
CVE-2023-27364
HIGH
Foxit PDF Editor - Remote Code Execution via XLS File Parsing
CVSS 7.8
CVE-2023-27363
HIGH
Foxit PDF Reader < 12.1.1.15289 and PDF Editor < 10.1.11.37866 - Remote Code Execution via exportXFAData Method
CVSS 7.8
CVE-2023-49074
HIGH
TP-Link EAP225 V3 v5.1.0 Build 20220926 - Unauthenticated Denial of Service via TDDP Network Requests
CVSS 7.4
CVE-2023-51573
CRITICAL
Voltronic Power ViewPower Pro - Auth Bypass
CVSS 9.8
CVE-2023-5389
CRITICAL
Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC - Fil...
CVSS 9.1
CVE-2023-50424
CRITICAL
SAP BTP Security Services Integration Library < 0.17.0 - Privilege Escalation
CVSS 9.1
CVE-2023-50423
CRITICAL
SAP XSSEC < 4.1.0 - Unauthenticated Privilege Escalation
CVSS 9.1
CVE-2023-50422
CRITICAL
SAP BTP Security Services Integration Library <2.17.0 and 3.0.0-<3.3.0 - Privilege Escalation
CVSS 9.1
CVE-2023-49583
CRITICAL
SAP @sap/xssec < 3.6.0 - Unauthenticated Privilege Escalation
CVSS 9.1
CVE-2023-39226
CRITICAL
Delta Electronics InfraSuite Device Master <1.0.7 - RCE
CVSS 9.8
CVE-2023-40151
CRITICAL
Red Lion SixTRAK and VersaTRAK Series - Privilege Escalation
CVSS 10.0
CVE-2023-42494
HIGH
EisBaer Scada < 3.0.6433.1964 - Exposed Dangerous Method or Function
CVSS 7.5
CVE-2023-3656
CRITICAL
cashit! < 03.a06rks_2023.02.37 - Unauthenticated Remote Code Execution via HTTP Endpoint
CVSS 9.8
CVE-2023-3655
HIGH
cashIT! - PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH 03.A06rk...
CVSS 7.5
CVE-2023-40150
CRITICAL
Softneta MedDream PACS < 7.2.8.810 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-3612
HIGH
Govee Home < 5.8.01 - Unauthenticated JavaScript Execution via WebView URL Handling
CVSS 8.2
CVE-2023-39214
HIGH
Zoom Client SDK <5.15.5 - Info Disclosure
CVSS 7.6
CVE-2023-36853
HIGH
Keysight Geolocation Server <v2.4.2 - Code Injection
CVSS 7.8
CVE-2023-33921
MEDIUM
CP-8031/CP-8050 <CPCI85 V05 - Info Disclosure
CVSS 6.8
CVE-2023-34227
MEDIUM
JetBrains TeamCity < 2023.05 - Brute Force Attack via Specific Endpoint
CVSS 5.3
Details
Vulnerabilities
167
Exploit Likelihood
Low