VYPR

CWE-749

Exposed Dangerous Method or Function

BaseIncompleteLikelihood: Low

Description

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-500

CVEs mapped to this weakness (184)

page 5 of 10
  • CVE-2025-14493HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14492HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14491HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14490HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14489HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-14488HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute…

  • CVE-2025-47353HigNov 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing request sent from GVM.

  • CVE-2024-6510HigSep 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

  • CVE-2024-6689HigJul 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM.

  • CVE-2023-51577HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Voltronic Power ViewPower setShutdown Exposed Dangerous Method Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Voltronic Power ViewPower. An attacker must first obtain the ability to execute…

  • CVE-2023-39493HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor exportAsText Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-37330HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF exportAsText Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-27365HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Editor DOC File Parsing Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-27364HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that…

  • CVE-2023-36853HigJul 19, 2023
    risk 0.51cvss 7.8epss 0.00

    ​In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.

  • CVE-2022-37365HigMar 29, 2023
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2020-12927HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system.

  • CVE-2020-12928HigOct 13, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.

  • CVE-2019-5015HigMar 8, 2019
    risk 0.51cvss 7.8epss 0.01

    A local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user with local access can use this vulnerability to escalate their privileges to root. An attacker would need local access to the machine for a…

  • CVE-2026-45805HigJul 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to…