VYPR

CWE-749

Exposed Dangerous Method or Function

BaseIncompleteLikelihood: Low

Description

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-500

CVEs mapped to this weakness (184)

page 6 of 10
  • CVE-2025-14713HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.

  • CVE-2026-28400HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed directly to the underlying…

  • CVE-2025-37097HigJul 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service

  • CVE-2025-3698HigApr 16, 2025
    risk 0.49cvss 7.5epss 0.00

    Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.

  • CVE-2023-51578HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Voltronic Power ViewPower. Authentication is not required to exploit…

  • CVE-2023-42032HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Visualware MyConnection Server doRTAAccessUPass Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Visualware MyConnection Server. Authentication is not required…

  • CVE-2023-49074HigApr 9, 2024
    risk 0.49cvss 7.4epss 0.13

    A denial of service vulnerability exists in the TDDP functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of network requests can lead to reset to factory settings. An attacker can send a sequence of…

  • CVE-2023-42494HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    EisBaer Scada - CWE-749: Exposed Dangerous Method or Function

  • CVE-2023-3655HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a dangerous methods, that allows to leak the database (system settings, user accounts,...). This vulnerability can be triggered by an HTTP…

  • CVE-2023-39214HigAug 8, 2023
    risk 0.49cvss 7.6epss 0.01

    Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

  • CVE-2021-33639HigMar 8, 2023
    risk 0.49cvss 7.5epss 0.00

    REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.

  • CVE-2021-26614HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.02

    ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.

  • CVE-2025-24359HigJan 24, 2025
    risk 0.48cvss 8.4epss 0.00

    ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of the application using the library. The…

  • CVE-2026-18901HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed…

  • CVE-2026-44698HigMay 29, 2026
    risk 0.47cvss 8.3epss 0.00

    Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on…

  • CVE-2026-4051HigMay 26, 2026
    risk 0.47cvss 7.2epss 0.00

    IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.

  • CVE-2023-39470HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The…

  • CVE-2023-39468HigMay 3, 2024
    risk 0.47cvss 7.2epss 0.02

    Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway.…

  • CVE-2026-35488HigApr 7, 2026
    risk 0.46cvss 8.1epss 0.00

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_permission() returns True for…

  • CVE-2025-47366HigFeb 2, 2026
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.