Weaknesses of type CWE-749

190 results

Exposição de método ou função perigosa

Uma função ou método sensível fica acessível quando não deveria estar — seja por falta de controle de acesso, visibilidade errada ou ausência de autenticação. Isso permite que atacantes invoquem operações críticas (deletar dados, alterar configurações, executar código) que deveriam ser restritas.

Example

Uma API REST expõe um endpoint `/admin/reset-db` sem autenticação, permitindo qualquer pessoa deletar toda a base de dados. Ou uma classe Java com método `public` que executa operações administrativas, acessível por classes não autorizadas.

How to mitigate

Implemente controle de acesso explícito: valide permissões antes de executar qualquer operação sensível, use visibilidade apropriada (private/protected), autentique e autorize requisições em todas as entradas perigosas, e siga o princípio do menor privilégio.

CVE-2025-14494HIGHRealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-14493HIGHRealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-14496HIGHRealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-14497HIGHRealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-6689HIGHLocal privilege escalation vulnerability in baramundi Management Agent via MSI InstallerEPSS 0.2%CVE-2024-55923MEDIUMCross-Site Request Forgery in Indexed Search Module in TYPO3EPSS 0.2%CVE-2024-55920MEDIUMCross-Site Request Forgery in Dashboard Module in TYPO3EPSS 0.2%CVE-2024-55922MEDIUMCross-Site Request Forgery in Form Framework Module in TYPO3EPSS 0.2%CVE-2026-92612LOWIn Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::asEPSS 0.2%CVE-2026-7516MEDIUMA vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allowEPSS 0.2%CVE-2026-48783MEDIUMPostiz has an unauthenticated billing-enforcement bypass via /public/modify-subscriptionEPSS 0.2%CVE-2025-34114HIGHOpenBlow Missing Critical Security HeadersEPSS 0.2%CVE-2026-25255HIGHExposed function in Qualcomm Package Manager and Qualcomm Software Center.EPSS 0.2%CVE-2026-8108HIGHFuji Electric Tellus Exposed Dangerous Method or FunctionEPSS 0.1%CVE-2026-47899HIGHArbitrary File Read, Write, Rename, and Delete in LogseqEPSS 0.1%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.1%CVE-2026-86711HIGHelecterm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC BridgeEPSS 0.1%CVE-2026-18263HIGHParallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation VulnerabilityEPSS 0.1%CVE-2026-20293HIGHCisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass VulnerabilityEPSS 0.1%CVE-2026-18262HIGHParallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation VulnerabilityEPSS 0.1%