Weaknesses of type CWE-749

190 results

Exposição de método ou função perigosa

Uma função ou método sensível fica acessível quando não deveria estar — seja por falta de controle de acesso, visibilidade errada ou ausência de autenticação. Isso permite que atacantes invoquem operações críticas (deletar dados, alterar configurações, executar código) que deveriam ser restritas.

Example

Uma API REST expõe um endpoint `/admin/reset-db` sem autenticação, permitindo qualquer pessoa deletar toda a base de dados. Ou uma classe Java com método `public` que executa operações administrativas, acessível por classes não autorizadas.

How to mitigate

Implemente controle de acesso explícito: valide permissões antes de executar qualquer operação sensível, use visibilidade apropriada (private/protected), autentique e autorize requisições em todas as entradas perigosas, e siga o princípio do menor privilégio.

CVE-2025-64443HIGHDNS Rebinding vulnerability present when running MCP Gateway in sse or streaming modeEPSS 0.4%CVE-2026-5173HIGHExposed Dangerous Method or Function in GitLabEPSS 0.4%CVE-2024-32764CRITICALmyQNAPcloud LinkEPSS 0.4%CVE-2025-3698HIGHInterface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.EPSS 0.4%CVE-2023-39493HIGHPDF-XChange Editor exportAsText Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-61907HIGHIcinga 2 API users could access restricted values in filter expressionsEPSS 0.4%CVE-2026-3483HIGHAn exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.EPSS 0.4%CVE-2023-33921MEDIUMA vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05).EPSS 0.4%CVE-2023-39505MEDIUMPDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-39495MEDIUMPDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-45805HIGHPenpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCEEPSS 0.4%CVE-2026-35488HIGHTandoor Recipes — CustomIsShared permits DELETE/PUT on RecipeBook by shared (read-only) usersEPSS 0.4%CVE-2024-12651HIGHSensitive Data Exposure in PTT Inc.'s HGS Mobile AppEPSS 0.4%CVE-2026-52877HIGHStreambert : Insecure Protocol Execution in open-external IPC HandlerEPSS 0.4%CVE-2024-13242CRITICALSwift Mailer - Moderately critical - Access bypass - SA-CONTRIB-2024-006EPSS 0.4%CVE-2026-4051HIGHIBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code ExecutionEPSS 0.4%CVE-2024-55921HIGHCross-Site Request Forgery in Extension Manager Module in TYPO3EPSS 0.4%CVE-2025-43955LOWTwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in EPSS 0.4%CVE-2024-4739MEDIUMMXsecurity License Generation Function DisclosureEPSS 0.4%CVE-2024-6863MEDIUMEncryption of Arbitrary Files with Attacker-Controlled Key in h2oai/h2o-3EPSS 0.4%