CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

167 vulnerabilities with CWE-749
CVE-2023-26478 MEDIUM
XWiki Platform <14.3-rc-1 - Info Disclosure
CVSS 6.6
CVE-2022-31491 CRITICAL
Voltronic Power ViewPower <1.04-24215, ViewPower Pro <2.0-22165, Po...
CVSS 10.0
CVE-2022-37365 HIGH
PDF-XChange Editor - Arbitrary File Write via JavaScript saveAs Method
CVSS 7.8
CVE-2022-46156 HIGH
Grafana Synthetic Monitoring <0.12.0 - Info Disclosure
CVSS 7.2
CVE-2022-4136 CRITICAL
leadshop 1.4.15 - Remote Code Execution via Exposed Method in leadshop.php
CVSS 9.8
CVE-2021-33639 HIGH
openatom openeuler_kernel < 4.19.90-2211.4.0.0177 - Unauthenticated Memory Protection Bypass via SVM REMAP Command
CVSS 7.5
CVE-2021-34996 HIGH
Commvault CommCell - Authenticated Remote Code Execution via Demo_ExecuteProcessOnGroup Workflow
CVSS 8.8
CVE-2021-35243 MEDIUM
Web Help Desk <12.7.7 - Info Disclosure
CVSS 5.3
CVE-2021-42128 CRITICAL
Ivanti Avalanche < 6.3.3 - Privilege Escalation via Enterprise Server Service
CVSS 9.8
CVE-2021-26614 HIGH
IpTime C200 Firmware < 1.060 - Remote Code Execution via ius_get.cgi
CVSS 7.5
CVE-2021-28809 CRITICAL
QNAP Hybrid Backup Sync < 3.0.210507 - Improper Access Control
CVSS 9.8
CVE-2020-2503 CRITICAL
QNAP QES < 2.1.1 - Stored Cross-Site Scripting in File Station
CVSS 9.0
CVE-2020-12927 HIGH
AMD VBIOS Flash Tool SDK - Privilege Escalation
CVSS 7.8
CVE-2020-12912 MEDIUM
AMD Energy Driver for Linux - Unauthenticated Side Channel Attack via RAPL Interface
CVSS 5.5
CVE-2020-27123 MEDIUM
Cisco AnyConnect Secure Mobility Client for Windows - Info Disclosure
CVSS 5.5
CVE-2020-12928 HIGH
AMD Ryzen Master V15 - Privilege Escalation
CVSS 7.8
CVE-2020-3513 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.7
CVE-2020-3416 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.7
CVE-2020-17391 MEDIUM
Parallels Desktop 15.1.3-47255 - Info Disclosure
CVSS 6.5
CVE-2020-17388 HIGH
Marvell QConvergeConsole 5.5.0.64 - RCE
CVSS 8.8
CVE-2020-8212 CRITICAL
Citrix XenMobile <10.12 - Privilege Escalation
CVSS 9.8
CVE-2020-15623 CRITICAL
CentOS Web Panel cwp-e17.0.9.8.923 - Root File Write via ajax_mod_security
CVSS 9.8
CVE-2020-10268 MEDIUM
KUKA KR C4 Firmware - Unauthenticated Denial of Service via Task Manager Service Termination
CVSS 6.1
CVE-2019-20923 MEDIUM
MongoDB 4.0.0-4.0.6 - Denial of Service via Unhandled JavaScript Exception
CVSS 6.5
CVE-2019-18342 CRITICAL
Control Center Server <1.5.0 - Info Disclosure
CVSS 9.9
Details
Vulnerabilities 167
Exploit Likelihood Low