Weaknesses of type CWE-749

190 results

Exposição de método ou função perigosa

Uma função ou método sensível fica acessível quando não deveria estar — seja por falta de controle de acesso, visibilidade errada ou ausência de autenticação. Isso permite que atacantes invoquem operações críticas (deletar dados, alterar configurações, executar código) que deveriam ser restritas.

Example

Uma API REST expõe um endpoint `/admin/reset-db` sem autenticação, permitindo qualquer pessoa deletar toda a base de dados. Ou uma classe Java com método `public` que executa operações administrativas, acessível por classes não autorizadas.

How to mitigate

Implemente controle de acesso explícito: valide permissões antes de executar qualquer operação sensível, use visibilidade apropriada (private/protected), autentique e autorize requisições em todas as entradas perigosas, e siga o princípio do menor privilégio.

CVE-2025-5823MEDIUMAutel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-34227MEDIUMIn JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacksEPSS 0.5%CVE-2026-14620MEDIUMwebpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsEPSS 0.5%CVE-2023-3612HIGHUnprotected WebView access in Govee Home AppEPSS 0.5%CVE-2025-37097HIGHA vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of serviceEPSS 0.5%CVE-2022-46156HIGHGrafana's default installation of `synthetic-monitoring-agent` exposes sensitive informationEPSS 0.5%CVE-2021-33639HIGHREMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.EPSS 0.5%CVE-2026-48056CRITICALStreambert Vulnerable to Arbitrary Binary Execution via Downloader IPC HandlerEPSS 0.5%CVE-2025-14713HIGHAn Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote atEPSS 0.5%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.5%CVE-2023-3655HIGHUnauthenticated Remote Database ExfiltrationEPSS 0.5%CVE-2020-12912A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power LEPSS 0.5%CVE-2024-47005HIGHSharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficientEPSS 0.5%CVE-2026-61793MEDIUMNuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameterEPSS 0.5%CVE-2026-30797CRITICALRustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled ServerEPSS 0.5%CVE-2026-18901HIGHH3C NX15 Web API esps service.add routineEPSS 0.5%CVE-2025-5748HIGHWOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-30921CRITICALOneUptime Synthetic Monitor RCE via exposed Playwright browser objectEPSS 0.4%CVE-2026-2275CRITICALCVE-2026-2275EPSS 0.4%CVE-2025-53964CRITICALGoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary andEPSS 0.4%