Weaknesses of type CWE-749

190 results

Exposição de método ou função perigosa

Uma função ou método sensível fica acessível quando não deveria estar — seja por falta de controle de acesso, visibilidade errada ou ausência de autenticação. Isso permite que atacantes invoquem operações críticas (deletar dados, alterar configurações, executar código) que deveriam ser restritas.

Example

Uma API REST expõe um endpoint `/admin/reset-db` sem autenticação, permitindo qualquer pessoa deletar toda a base de dados. Ou uma classe Java com método `public` que executa operações administrativas, acessível por classes não autorizadas.

How to mitigate

Implemente controle de acesso explícito: valide permissões antes de executar qualquer operação sensível, use visibilidade apropriada (private/protected), autentique e autorize requisições em todas as entradas perigosas, e siga o princípio do menor privilégio.

CVE-2023-40150CRITICALSoftneta MedDream PACS Exposed Dangerous Method or FunctionEPSS 1.3%CVE-2023-42032HIGHVisualware MyConnection Server doRTAAccessUPass Exposed Dangerous Method Information Disclosure VulnerabilityEPSS 1.2%CVE-2025-9611HIGHMicrosoft Playwright MCP Server < 0.0.40 DNS Rebinding via Missing Origin Header ValidationEPSS 1.2%CVE-2026-54753MEDIUMNx: `nx graph` dev server permissive CORS policyEPSS 1.2%CVE-2023-39226CRITICALDelta Electronics InfraSuite Device Master Exposed Dangerous Method Or FunctionEPSS 1.2%CVE-2026-30957CRITICALOneUptime Synthetic Monitor RCE via exposed Playwright browser objectEPSS 1.2%CVE-2023-40151CRITICALRed Lion Controls Sixnet RTU Exposed Dangerous Method Or FunctionEPSS 1.1%CVE-2023-50424CRITICALEscalation of Privileges in SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go)EPSS 1.1%CVE-2023-51584HIGHVoltronic Power ViewPower USBCommEx shutdown Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-50423CRITICALEscalation of Privileges in SAP BTP Security Services Integration Library ([Python] cloud-pysec)EPSS 1.1%CVE-2023-49583CRITICALEscalation of Privileges in SAP BTP Security Services Integration Library ([Node.js] @sap/xssec)EPSS 1.1%CVE-2025-59403CRITICALThe Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsibEPSS 1.1%CVE-2026-77521CRITICALMaxKB: Prompt-injectable agent can lead to command executionEPSS 1.0%CVE-2023-3656CRITICALUnauthenticated Remote Code ExecutionEPSS 1.0%CVE-2022-4136HIGHExposed Dangerous Method or Function in qmpaas/leadshopEPSS 1.0%CVE-2023-39214HIGHExposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via netwoEPSS 1.0%CVE-2026-22208CRITICALOpenS100 Portrayal Engine Unrestricted Lua Standard Library AccessEPSS 0.9%CVE-2026-24118CRITICALVM2 Sandbox Breakout Through __lookupGetter__EPSS 0.9%CVE-2021-35243MEDIUMHTTP PUT & DELETE Methods EnabledEPSS 0.9%CVE-2026-53633CRITICALVitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCEEPSS 0.9%