Fallos del tipo CWE-749

190 resultados

Método ou função perigosa exposta

Ocorre quando uma aplicação disponibiliza públicamente um método ou função que não deveria ser acessível, permitindo que um atacante execute operações privilegiadas ou sensíveis. O risco é que funcionalidades internas críticas (debug, administração, operações de sistema) fiquem acessíveis sem autenticação ou validação adequada.

Ejemplo

Um serviço web expõe um endpoint remoto para rebootar o servidor ou executar comandos SQL diretos, ou uma biblioteca Python publica uma função de teste que apaga dados sem verificação. Qualquer cliente consegue chamar esses métodos e comprometer a integridade do sistema.

Cómo mitigar

Marque métodos sensíveis com modificadores de acesso restritivos (private, protected), revise regularmente quais funções estão realmente expostas na API pública, e implemente autenticação e autorização explícitas antes de permitir operações críticas. Use linters e ferramentas de análise estática para detectar exposições acidentais.

CVE-2026-5173HIGHExposed Dangerous Method or Function in GitLabEPSS 0.4%CVE-2025-64443HIGHDNS Rebinding vulnerability present when running MCP Gateway in sse or streaming modeEPSS 0.4%CVE-2024-32764CRITICALmyQNAPcloud LinkEPSS 0.4%CVE-2025-3698HIGHInterface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.EPSS 0.4%CVE-2023-39493HIGHPDF-XChange Editor exportAsText Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-61907HIGHIcinga 2 API users could access restricted values in filter expressionsEPSS 0.4%CVE-2026-3483HIGHAn exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.EPSS 0.4%CVE-2023-33921MEDIUMA vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05).EPSS 0.4%CVE-2023-39505MEDIUMPDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-39495MEDIUMPDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-45805HIGHPenpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCEEPSS 0.4%CVE-2026-35488HIGHTandoor Recipes — CustomIsShared permits DELETE/PUT on RecipeBook by shared (read-only) usersEPSS 0.4%CVE-2024-12651HIGHSensitive Data Exposure in PTT Inc.'s HGS Mobile AppEPSS 0.4%CVE-2026-52877HIGHStreambert : Insecure Protocol Execution in open-external IPC HandlerEPSS 0.4%CVE-2024-13242CRITICALSwift Mailer - Moderately critical - Access bypass - SA-CONTRIB-2024-006EPSS 0.4%CVE-2026-4051HIGHIBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code ExecutionEPSS 0.4%CVE-2024-55921HIGHCross-Site Request Forgery in Extension Manager Module in TYPO3EPSS 0.4%CVE-2025-43955LOWTwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expression injection in EPSS 0.4%CVE-2024-6863MEDIUMEncryption of Arbitrary Files with Attacker-Controlled Key in h2oai/h2o-3EPSS 0.4%CVE-2024-4739MEDIUMMXsecurity License Generation Function DisclosureEPSS 0.4%