VYPR

CWE-749

Exposed Dangerous Method or Function

BaseIncompleteLikelihood: Low

Description

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-500

CVEs mapped to this weakness (184)

page 9 of 10
  • CVE-2026-49993MedJun 12, 2026
    risk 0.30cvss 5.7epss 0.00

    Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when…

  • CVE-2026-45670MedJun 12, 2026
    risk 0.28cvss 5.4epss 0.00

    Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using…

  • CVE-2026-7516MedJun 10, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents.

  • CVE-2024-55945MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-55922MedJan 14, 2025
    risk 0.28cvss 5.4epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2026-6402MedMay 12, 2026
    risk 0.27cvss 5.3epss 0.00

    webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers…

  • CVE-2025-30359MedJun 3, 2025
    risk 0.27cvss 5.3epss 0.00

    webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when they access a malicious web site. Because the request for classic script by a script tag is not…

  • CVE-2025-24361MedJan 25, 2025
    risk 0.27cvss 5.3epss 0.00

    Nuxt is an open-source web development framework for Vue.js. Source code may be stolen during dev when using version 3.0.0 through 3.15.12 of the webpack builder or version 3.12.2 through 3.152 of the rspack builder and a victim opens a malicious web site. Because the request…

  • CVE-2024-29880MedMar 21, 2024
    risk 0.27cvss 4.2epss 0.00

    In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

  • CVE-2026-14620MedJul 3, 2026
    risk 0.24cvss 4.7epss 0.00

    webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's…

  • CVE-2026-48783MedJun 17, 2026
    risk 0.24cvss 4.8epss 0.00

    Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's…

  • CVE-2024-55923MedJan 14, 2025
    risk 0.21cvss 4.3epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-55920MedJan 14, 2025
    risk 0.21cvss 4.3epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-55894MedJan 14, 2025
    risk 0.21cvss 4.3epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-55893MedJan 14, 2025
    risk 0.21cvss 4.3epss 0.00

    TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing…

  • CVE-2024-51992MedNov 11, 2024
    risk 0.20cvss 4.1epss 0.00

    Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue (CWE-749: Exposed Dangerous Method or Function) in the Orchid Platform’s asynchronous modal…

  • CVE-2025-43955LowApr 20, 2025
    risk 0.14cvss 2.2epss 0.00

    TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.

  • CVE-2026-44107HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.

  • CVE-2025-53827CriJul 6, 2026
    risk 0.00cvss 9.1epss 0.00

    ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative…

  • CVE-2026-45489MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Microsoft Edge (Chromium-based) Spoofing Vulnerability