CWE-749
187 CVEs • Abstraction: Base • Likelihood of Exploit: Low
Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
CVEs (187)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available pro...Show more |
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload th...Show more |
1Beckhoff 2Embedded Pc Images TwincatMay 6, 2026 Oct 5, 2016 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Dis...Show more |
An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafted HTML document. |
1Redhat 1Jboss Enterprise Application Platform Aug 14, 2026 Apr 28, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met...Show more |
1Redhat 1Jboss Enterprise Application Platform Aug 14, 2026 Apr 28, 2010 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho...Show more |
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the...Show more |