Fallos del tipo CWE-749

190 resultados

Método ou função perigosa exposta

Ocorre quando uma aplicação disponibiliza públicamente um método ou função que não deveria ser acessível, permitindo que um atacante execute operações privilegiadas ou sensíveis. O risco é que funcionalidades internas críticas (debug, administração, operações de sistema) fiquem acessíveis sem autenticação ou validação adequada.

Ejemplo

Um serviço web expõe um endpoint remoto para rebootar o servidor ou executar comandos SQL diretos, ou uma biblioteca Python publica uma função de teste que apaga dados sem verificação. Qualquer cliente consegue chamar esses métodos e comprometer a integridade do sistema.

Cómo mitigar

Marque métodos sensíveis com modificadores de acesso restritivos (private, protected), revise regularmente quais funções estão realmente expostas na API pública, e implemente autenticação e autorização explícitas antes de permitir operações críticas. Use linters e ferramentas de análise estática para detectar exposições acidentais.

CVE-2019-5015CRITICALA local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user witEPSS 0.9%CVE-2026-45489MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.9%CVE-2024-25675CRITICALAn issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related toEPSS 0.8%CVE-2022-31491CRITICALVoltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote atEPSS 0.8%CVE-2020-2503CRITICALStored cross-site scripting vulnerability in QESEPSS 0.8%CVE-2023-5389CRITICAL An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUEPSS 0.8%CVE-2024-27444CRITICALlangchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and executEPSS 0.8%CVE-2022-37365HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.7%CVE-2026-41283CRITICALOpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code executiEPSS 0.7%CVE-2023-42494HIGH EisBaer Scada - CWE-749: Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2026-8109MEDIUMAn exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to EPSS 0.7%CVE-2023-26478MEDIUMorg.xwiki.platform:xwiki-platform-store-filesystem-oldcore has Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2025-53827CRITICALownCloud Core: Updater has an exposed dangerous method or functionEPSS 0.6%CVE-2026-68823CRITICALAzure Confidential Ledger Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55454CRITICALAppsmith: Caddy admin API exposed without authenticationEPSS 0.6%CVE-2025-30359MEDIUMwebpack-dev-server users' source code may be stolen when they access a malicious web siteEPSS 0.6%CVE-2023-27365HIGHFoxit PDF Editor DOC File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-27364HIGHFoxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2019-13945A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-1200 CPU family < V4.x EPSS 0.5%CVE-2020-17391MEDIUMThis vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker mEPSS 0.5%