VYPR

CWE-749

Exposed Dangerous Method or Function

BaseIncompleteLikelihood: Low

Description

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-500

CVEs mapped to this weakness (184)

page 4 of 10
  • CVE-2016-7462HigDec 29, 2016
    risk 0.55cvss 8.5epss 0.02

    The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.

  • CVE-2023-27363HigMay 3, 2024
    risk 0.54cvss 7.8epss 0.47

    Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the…

  • CVE-2019-12948HigJul 29, 2019
    risk 0.54cvss 8.3epss 0.02

    A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or…

  • CVE-2026-30797HigMar 5, 2026
    risk 0.53cvss 8.1epss 0.00

    Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated…

  • CVE-2024-47005HigOct 25, 2024
    risk 0.53cvss 8.1epss 0.00

    Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.

  • CVE-2023-3612HigSep 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

  • CVE-2016-9469HigMar 28, 2017
    risk 0.53cvss 8.2epss 0.02

    Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be exploited by an…

  • CVE-2026-22812HigJan 12, 2026
    risk 0.52cvss 8.8epss 0.17

    OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is…

  • CVE-2025-5748HigJun 6, 2025
    risk 0.52cvss 8.0epss 0.00

    WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV Charger. Although authentication is required to exploit…

  • CVE-2024-55924HigJan 14, 2025
    risk 0.52cvss 8.0epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2023-50424CriDec 12, 2023
    risk 0.52cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the…

  • CVE-2023-50423CriDec 12, 2023
    risk 0.52cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

  • CVE-2023-50422CriDec 12, 2023
    risk 0.52cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated…

  • CVE-2026-8108HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.

  • CVE-2026-3483HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

  • CVE-2026-20423HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956.

  • CVE-2025-14497HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14496HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14495HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14494HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…