Fallos del tipo CWE-749

190 resultados

Método ou função perigosa exposta

Ocorre quando uma aplicação disponibiliza públicamente um método ou função que não deveria ser acessível, permitindo que um atacante execute operações privilegiadas ou sensíveis. O risco é que funcionalidades internas críticas (debug, administração, operações de sistema) fiquem acessíveis sem autenticação ou validação adequada.

Ejemplo

Um serviço web expõe um endpoint remoto para rebootar o servidor ou executar comandos SQL diretos, ou uma biblioteca Python publica uma função de teste que apaga dados sem verificação. Qualquer cliente consegue chamar esses métodos e comprometer a integridade do sistema.

Cómo mitigar

Marque métodos sensíveis com modificadores de acesso restritivos (private, protected), revise regularmente quais funções estão realmente expostas na API pública, e implemente autenticação e autorização explícitas antes de permitir operações críticas. Use linters e ferramentas de análise estática para detectar exposições acidentais.

CVE-2023-40150CRITICALSoftneta MedDream PACS Exposed Dangerous Method or FunctionEPSS 1.3%CVE-2023-42032HIGHVisualware MyConnection Server doRTAAccessUPass Exposed Dangerous Method Information Disclosure VulnerabilityEPSS 1.2%CVE-2025-9611HIGHMicrosoft Playwright MCP Server < 0.0.40 DNS Rebinding via Missing Origin Header ValidationEPSS 1.2%CVE-2026-54753MEDIUMNx: `nx graph` dev server permissive CORS policyEPSS 1.2%CVE-2023-39226CRITICALDelta Electronics InfraSuite Device Master Exposed Dangerous Method Or FunctionEPSS 1.2%CVE-2026-30957CRITICALOneUptime Synthetic Monitor RCE via exposed Playwright browser objectEPSS 1.2%CVE-2023-40151CRITICALRed Lion Controls Sixnet RTU Exposed Dangerous Method Or FunctionEPSS 1.1%CVE-2023-51584HIGHVoltronic Power ViewPower USBCommEx shutdown Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-50424CRITICALEscalation of Privileges in SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go)EPSS 1.1%CVE-2023-50423CRITICALEscalation of Privileges in SAP BTP Security Services Integration Library ([Python] cloud-pysec)EPSS 1.1%CVE-2023-49583CRITICALEscalation of Privileges in SAP BTP Security Services Integration Library ([Node.js] @sap/xssec)EPSS 1.1%CVE-2025-59403CRITICALThe Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsibEPSS 1.1%CVE-2023-3656CRITICALUnauthenticated Remote Code ExecutionEPSS 1.0%CVE-2022-4136HIGHExposed Dangerous Method or Function in qmpaas/leadshopEPSS 1.0%CVE-2023-39214HIGHExposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via netwoEPSS 1.0%CVE-2026-22208CRITICALOpenS100 Portrayal Engine Unrestricted Lua Standard Library AccessEPSS 0.9%CVE-2026-24118CRITICALVM2 Sandbox Breakout Through __lookupGetter__EPSS 0.9%CVE-2021-35243MEDIUMHTTP PUT & DELETE Methods EnabledEPSS 0.9%CVE-2026-53633CRITICALVitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCEEPSS 0.9%CVE-2019-5015CRITICALA local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user witEPSS 0.9%