CWE-749

Low likelihood

Exposed Dangerous Method or Function

Parent: CWE-284 - Improper Access Control

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

178 vulnerabilities with CWE-749
CVE-2020-27123 MEDIUM
Cisco AnyConnect Secure Mobility Client for Windows - Info Disclosure
CVSS 5.5
CVE-2020-12928 HIGH
AMD Ryzen Master V15 - Privilege Escalation
CVSS 7.8
CVE-2020-3513 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.7
CVE-2020-3416 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.7
CVE-2020-17391 MEDIUM
Parallels Desktop 15.1.3-47255 - Info Disclosure
CVSS 6.5
CVE-2020-17388 HIGH
Marvell QConvergeConsole 5.5.0.64 - RCE
CVSS 8.8
CVE-2020-8212 CRITICAL
Citrix XenMobile <10.12 - Privilege Escalation
CVSS 9.8
CVE-2020-15623 CRITICAL
CentOS Web Panel cwp-e17.0.9.8.923 - Root File Write via ajax_mod_security
CVSS 9.8
CVE-2020-10268 MEDIUM
KUKA KR C4 Firmware - Unauthenticated Denial of Service via Task Manager Service Termination
CVSS 6.1
CVE-2019-20923 MEDIUM
MongoDB 4.0.0-4.0.6 - Denial of Service via Unhandled JavaScript Exception
CVSS 6.5
CVE-2019-18342 CRITICAL
Control Center Server <1.5.0 - Info Disclosure
CVSS 9.9
CVE-2019-13945 MEDIUM
SIMATIC S7-1200 and S7-200 SMART CPU Families - Unauthenticated Exposed Dangerous Method via UART Interface
CVSS 6.8
CVE-2019-12948 HIGH
Polycom Unified Communications Software < 5.8.5.1256 / < 5.9.0 - RCE or DoS
CVSS 8.3
CVE-2019-4386 MEDIUM
IBM DB2 11.1.3-11.1.3.2 - Authenticated Denial of Service via Exposed Function
CVSS 6.5
CVE-2019-10918 HIGH
SIMATIC PCS 7 <8.0, <8.1 with WinCC <7.3 Upd19, <8.2 with WinCC <7....
CVSS 8.8
CVE-2019-5015 HIGH
Pixar Renderman <22.3.0 - Privilege Escalation
CVSS 7.8
CVE-2018-19322 HIGH KEV
GIGABYTE APP Center <1.05.21 - Privilege Escalation
CVSS 7.8
CVE-2018-10931 CRITICAL
Cobbler 2.6.x - Privilege Escalation
CVSS 9.8
CVE-2018-8868 MEDIUM
Medtronic MyCareLink Monitor - Info Disclosure
CVSS 6.2
CVE-2018-8949 MEDIUM
MISP <2.4.89 - Privilege Escalation
CVSS 4.3
CVE-2017-2735 HIGH
TIT-AL00 <TIT-AL00C583B214 - Privilege Escalation
CVSS 7.1
CVE-2016-9469 HIGH
GitLab 8.12.0-8.14.2 - Authenticated Issue and Merge Request Deletion
CVSS 8.2
CVE-2016-7462 HIGH
VMware vROps <6.4.0 - Deserialization
CVSS 8.5
CVE-2014-5415 CRITICAL
Beckhoff Embedded PC <2014-10-22 - RCE
CVSS 9.1
CVE-2014-0758
ICONICS GENESIS32 8.0 8.02 8.04 8.05 - Remote Code Execution via GenLaunch.htm ActiveX Control
Details
Vulnerabilities 178
Exploit Likelihood Low