Falhas do tipo CWE-749

190 resultados

Exposição de método ou função perigosa

Quando uma aplicação disponibiliza publicamente um método ou função que não deveria ser acessível, permitindo que atacantes a executem com consequências graves. O problema é expor funcionalidades sensíveis (como deleção de dados, mudança de permissões ou acesso a recursos críticos) sem validação adequada de quem está chamando.

Exemplo

Uma API REST expõe um endpoint `/admin/deleteUser` sem autenticação ou apenas com verificação de token fraco, permitindo qualquer pessoa deletar usuários da plataforma. Ou uma biblioteca carrega um método de configuração interna que permite alterar parâmetros de segurança diretamente via reflexão.

Como mitigar

Aplique princípio do menor privilégio: mantenha métodos sensíveis privados ou protegidos, exporte apenas o necessário e força autenticação + autorização rigorosa em tudo que fica acessível. Implemente validação de entrada e auditoria de quem acessa recursos críticos.

CVE-2019-5015CRITICALA local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user witEPSS 0.9%CVE-2026-45489MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.9%CVE-2024-25675CRITICALAn issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related toEPSS 0.8%CVE-2022-31491CRITICALVoltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote atEPSS 0.8%CVE-2020-2503CRITICALStored cross-site scripting vulnerability in QESEPSS 0.8%CVE-2023-5389CRITICAL An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUEPSS 0.8%CVE-2024-27444CRITICALlangchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and executEPSS 0.8%CVE-2022-37365HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.7%CVE-2026-41283CRITICALOpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code executiEPSS 0.7%CVE-2023-42494HIGH EisBaer Scada - CWE-749: Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2026-8109MEDIUMAn exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to EPSS 0.7%CVE-2023-26478MEDIUMorg.xwiki.platform:xwiki-platform-store-filesystem-oldcore has Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2025-53827CRITICALownCloud Core: Updater has an exposed dangerous method or functionEPSS 0.6%CVE-2026-68823CRITICALAzure Confidential Ledger Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-55454CRITICALAppsmith: Caddy admin API exposed without authenticationEPSS 0.6%CVE-2025-30359MEDIUMwebpack-dev-server users' source code may be stolen when they access a malicious web siteEPSS 0.6%CVE-2023-27365HIGHFoxit PDF Editor DOC File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-27364HIGHFoxit PDF Editor XLS File Parsing Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.5%CVE-2019-13945A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-1200 CPU family < V4.x EPSS 0.5%CVE-2020-17391MEDIUMThis vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.3-47255. An attacker mEPSS 0.5%