VYPR

CWE-749

Exposed Dangerous Method or Function

BaseIncompleteLikelihood: Low

Description

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-500

CVEs mapped to this weakness (195)

page 8 of 10
  • CVE-2024-6863MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This vulnerability makes it…

  • CVE-2024-55921HigJan 14, 2025
    risk 0.42cvss 7.5epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-27261MedApr 12, 2024
    risk 0.42cvss 6.4epss 0.00

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.

  • CVE-2020-17391MedAug 25, 2020
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw…

  • CVE-2019-4386MedJul 1, 2019
    risk 0.42cvss 6.5epss 0.02

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.

  • CVE-2026-86711HigSep 8, 2026
    risk 0.41cvss 7.4epss 0.00

    electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system…

  • CVE-2025-9611HigJan 7, 2026
    risk 0.40cvss —epss 0.01

    Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting…

  • CVE-2025-48415MedMay 21, 2025
    risk 0.40cvss 6.2epss 0.00

    A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" that could be exploited by an attacker to export or modify the device configuration, enable an SSH backdoor  or…

  • CVE-2024-35209MedJun 11, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.

  • CVE-2022-46156HigNov 30, 2022
    risk 0.40cvss 7.2epss 0.01

    The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The…

  • CVE-2020-10268MedJun 16, 2020
    risk 0.40cvss 6.1epss 0.00

    Critical services for operation can be terminated from windows task manager, bringing the manipulator to a halt. After this a Re-Calibration of the brakes needs to be performed. Be noted that this only can be accomplished either by a Kuka technician or by Kuka issued calibration…

  • CVE-2018-8868MedJul 3, 2018
    risk 0.40cvss 6.2epss 0.00

    Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable cardiac device. An attacker with physical access to the…

  • CVE-2026-20467MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue…

  • CVE-2026-44798HigMay 28, 2026
    risk 0.39cvss 7.1epss 0.01

    Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not intended to be user-editable.…

  • CVE-2025-68697HigDec 26, 2025
    risk 0.39cvss 7.1epss 0.00

    n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can invoke internal helper functions from…

  • CVE-2026-61793MedSep 17, 2026
    risk 0.38cvss —epss 0.01

    Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and base64url-decodes the fonts parameter…

  • CVE-2024-45747higAug 19, 2026
    risk 0.38cvss —epss —

    ### Summary A server-side template injection (SSTI) vulnerability exist that allows an authenticated administrator to upload FreeMarker templates containing malicious content that can execute OS commands and read from or write to arbitrary files on the server. These FreeMarker…

  • CVE-2026-75810MedSep 8, 2026
    risk 0.37cvss —epss 0.00

    Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS)…

  • CVE-2026-25266MedMay 4, 2026
    risk 0.36cvss 5.5epss 0.00

    Memory corruption while processing IOCTL command when device is in power-save state.

  • CVE-2023-39505MedMay 3, 2024
    risk 0.36cvss 5.5epss 0.00

    PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this…