CWE-749
Low likelihoodExposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
178 vulnerabilities with CWE-749
CVE-2023-39226
CRITICAL
Delta Electronics InfraSuite Device Master <1.0.7 - RCE
CVSS 9.8
CVE-2023-40151
CRITICAL
Red Lion SixTRAK and VersaTRAK Series - Privilege Escalation
CVSS 10.0
CVE-2023-42494
HIGH
EisBaer Scada < 3.0.6433.1964 - Exposed Dangerous Method or Function
CVSS 7.5
CVE-2023-3656
CRITICAL
cashit! < 03.a06rks_2023.02.37 - Unauthenticated Remote Code Execution via HTTP Endpoint
CVSS 9.8
CVE-2023-3655
HIGH
cashIT! - PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH 03.A06rk...
CVSS 7.5
CVE-2023-40150
CRITICAL
Softneta MedDream PACS < 7.2.8.810 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-3612
HIGH
Govee Home < 5.8.01 - Unauthenticated JavaScript Execution via WebView URL Handling
CVSS 8.2
CVE-2023-39214
HIGH
Zoom Client SDK <5.15.5 - Info Disclosure
CVSS 7.6
CVE-2023-36853
HIGH
Keysight Geolocation Server <v2.4.2 - Code Injection
CVSS 7.8
CVE-2023-33921
MEDIUM
CP-8031/CP-8050 <CPCI85 V05 - Info Disclosure
CVSS 6.8
CVE-2023-34227
MEDIUM
JetBrains TeamCity < 2023.05 - Brute Force Attack via Specific Endpoint
CVSS 5.3
CVE-2023-26478
MEDIUM
XWiki Platform <14.3-rc-1 - Info Disclosure
CVSS 6.6
CVE-2022-31491
CRITICAL
Voltronic Power ViewPower <1.04-24215, ViewPower Pro <2.0-22165, Po...
CVSS 10.0
CVE-2022-37365
HIGH
PDF-XChange Editor - Arbitrary File Write via JavaScript saveAs Method
CVSS 7.8
CVE-2022-46156
HIGH
Grafana Synthetic Monitoring <0.12.0 - Info Disclosure
CVSS 7.2
CVE-2022-4136
CRITICAL
leadshop 1.4.15 - Remote Code Execution via Exposed Method in leadshop.php
CVSS 9.8
CVE-2021-33639
HIGH
openatom openeuler_kernel < 4.19.90-2211.4.0.0177 - Unauthenticated Memory Protection Bypass via SVM REMAP Command
CVSS 7.5
CVE-2021-34996
HIGH
Commvault CommCell - Authenticated Remote Code Execution via Demo_ExecuteProcessOnGroup Workflow
CVSS 8.8
CVE-2021-35243
MEDIUM
Web Help Desk <12.7.7 - Info Disclosure
CVSS 5.3
CVE-2021-42128
CRITICAL
Ivanti Avalanche < 6.3.3 - Privilege Escalation via Enterprise Server Service
CVSS 9.8
CVE-2021-26614
HIGH
IpTime C200 Firmware < 1.060 - Remote Code Execution via ius_get.cgi
CVSS 7.5
CVE-2021-28809
CRITICAL
QNAP Hybrid Backup Sync < 3.0.210507 - Improper Access Control
CVSS 9.8
CVE-2020-2503
CRITICAL
QNAP QES < 2.1.1 - Stored Cross-Site Scripting in File Station
CVSS 9.0
CVE-2020-12927
HIGH
AMD VBIOS Flash Tool SDK - Privilege Escalation
CVSS 7.8
CVE-2020-12912
MEDIUM
AMD Energy Driver for Linux - Unauthenticated Side Channel Attack via RAPL Interface
CVSS 5.5
Details
Vulnerabilities
178
Exploit Likelihood
Low