CWE-749
176 CVEs • Abstraction: Base • Likelihood of Exploit: Low
Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
CVEs (176)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Polycom 2Unified Communications Software United Communications SoftwareJun 17, 2026 Jul 29, 2019 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin...Show more |
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714. |
1Siemens 4Simatic Pcs 7 Simatic WinccSimatic Wincc (tia Portal)+1 moreJun 17, 2026 May 14, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11...Show more |
A local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user with local access can use this vulnerability to escalate their privileges to root....Show more |
1Gigabyte 4Aorus Graphics Engine App CenterOc Guru Ii+1 moreNov 7, 2025 Dec 21, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/t...Show more |
2Cobbler Project Redhat2Cobbler SatelliteNov 21, 2024 Aug 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbi...Show more |
1Medtronic 224950 Mycarelink Monitor Firmware 24952 Mycarelink Monitor FirmwareJun 17, 2026 Jul 3, 2018 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains debug code meant to test the functionality of the monitor's communication interfaces, including the interface between the monitor and implantable c...Show more |
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attri...Show more |
TIT-AL00 smartphones with software versions earlier before TIT-AL00C583B214 have a exposed system interface vulnerability. The software provides a system interface for interaction with external applications, but calling...Show more |
Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available pro...Show more |
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload th...Show more |
1Beckhoff 2Embedded Pc Images TwincatMay 6, 2026 Oct 5, 2016 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Dis...Show more |
An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafted HTML document. |
1Redhat 1Jboss Enterprise Application Platform Apr 22, 2026 Apr 28, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 22, 2026 Apr 28, 2010 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho...Show more |
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the...Show more |