CWE-749: Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
172 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-30957 — OneUptime Synthetic Monitor RCE via exposed Playwright browser object
- CVE-2026-30921 — OneUptime Synthetic Monitor RCE via exposed Playwright browser object
- CVE-2024-32764 — myQNAPcloud Link
- CVE-2026-5173 — Exposed Dangerous Method or Function in GitLab
- CVE-2026-30797 — RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server
- CVE-2026-22812 — OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
- CVE-2024-5299 — D-Link D-View execMonitorScript Exposed Dangerous Method Remote Code Execution Vulnerability
- CVE-2025-34114 — OpenBlow Missing Critical Security Headers
- CVE-2025-24359 — ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape
- CVE-2026-48056 — Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler
- CVE-2026-55454 — Appsmith: Caddy admin API exposed without authentication
- CVE-2026-53633 — Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
- CVE-2024-47005 — Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users on
- CVE-2025-5748 — WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability
- CVE-2026-22208 — OpenS100 Portrayal Engine Unrestricted Lua Standard Library Access
- CVE-2026-3483 — An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei
- CVE-2026-20423 — In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
- CVE-2025-47353 — Exposed Dangerous Method or Function in Automotive Software platform based on QNX
- CVE-2025-14497 — RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2025-14496 — RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability
Recently published
- CVE-2026-20293 — Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
- CVE-2026-86711 — electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge
- CVE-2026-75810 — Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing
- CVE-2026-18263 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-18262 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
- CVE-2026-52877 — Streambert : Insecure Protocol Execution in open-external IPC Handler
- CVE-2026-66781 — Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication
- CVE-2026-48056 — Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler
- CVE-2026-18901 — H3C NX15 Web API esps service.add routine
- CVE-2026-20467 — In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatio
- CVE-2026-44107 — Exposed Reboot via Modbus
- CVE-2026-45805 — Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
- CVE-2026-53633 — Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
- CVE-2025-53827 — ownCloud Core: Updater has an exposed dangerous method or function
- CVE-2026-14620 — webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
- CVE-2026-54753 — Nx: `nx graph` dev server permissive CORS policy
- CVE-2026-55454 — Appsmith: Caddy admin API exposed without authentication
- CVE-2026-48783 — Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
- CVE-2026-49993 — @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)