Weaknesses of type CWE-749

190 results

Exposição de método ou função perigosa

Uma função ou método sensível fica acessível quando não deveria estar — seja por falta de controle de acesso, visibilidade errada ou ausência de autenticação. Isso permite que atacantes invoquem operações críticas (deletar dados, alterar configurações, executar código) que deveriam ser restritas.

Example

Uma API REST expõe um endpoint `/admin/reset-db` sem autenticação, permitindo qualquer pessoa deletar toda a base de dados. Ou uma classe Java com método `public` que executa operações administrativas, acessível por classes não autorizadas.

How to mitigate

Implemente controle de acesso explícito: valide permissões antes de executar qualquer operação sensível, use visibilidade apropriada (private/protected), autentique e autorize requisições em todas as entradas perigosas, e siga o princípio do menor privilégio.

CVE-2019-5015CRITICALA local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user witEPSS 0.9%CVE-2026-45489MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.9%CVE-2024-25675CRITICALAn issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related toEPSS 0.8%CVE-2022-31491CRITICALVoltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote atEPSS 0.8%CVE-2020-2503CRITICALStored cross-site scripting vulnerability in QESEPSS 0.8%CVE-2023-5389CRITICAL An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUEPSS 0.8%CVE-2024-27444CRITICALlangchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and executEPSS 0.8%CVE-2022-37365HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.7%CVE-2026-41283CRITICALOpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code executiEPSS 0.7%CVE-2023-42494HIGH EisBaer Scada - CWE-749: Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2026-8109MEDIUMAn exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to EPSS 0.7%CVE-2023-26478MEDIUMorg.xwiki.platform:xwiki-platform-store-filesystem-oldcore has Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2025-53827CRITICALownCloud Core: Updater has an exposed dangerous method or functionEPSS 0.6%CVE-2026-68823CRITICALAzure Confidential Ledger Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55454CRITICALAppsmith: Caddy admin API exposed without authenticationEPSS 0.6%CVE-2025-30359MEDIUMwebpack-dev-server users' source code may be stolen when they access a malicious web siteEPSS 0.6%CVE-2023-27365HIGHFoxit PDF Editor DOC File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-27364HIGHFoxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2019-13945A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-1200 CPU family < V4.x EPSS 0.5%CVE-2020-17391MEDIUMThis vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker mEPSS 0.5%