Falhas do tipo CWE-749

190 resultados

Exposição de método ou função perigosa

Quando uma aplicação disponibiliza publicamente um método ou função que não deveria ser acessível, permitindo que atacantes a executem com consequências graves. O problema é expor funcionalidades sensíveis (como deleção de dados, mudança de permissões ou acesso a recursos críticos) sem validação adequada de quem está chamando.

Exemplo

Uma API REST expõe um endpoint `/admin/deleteUser` sem autenticação ou apenas com verificação de token fraco, permitindo qualquer pessoa deletar usuários da plataforma. Ou uma biblioteca carrega um método de configuração interna que permite alterar parâmetros de segurança diretamente via reflexão.

Como mitigar

Aplique princípio do menor privilégio: mantenha métodos sensíveis privados ou protegidos, exporte apenas o necessário e força autenticação + autorização rigorosa em tudo que fica acessível. Implemente validação de entrada e auditoria de quem acessa recursos críticos.

CVE-2025-5823MEDIUMAutel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-34227MEDIUMIn JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacksEPSS 0.5%CVE-2026-14620MEDIUMwebpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsEPSS 0.5%CVE-2023-3612HIGHUnprotected WebView access in Govee Home AppEPSS 0.5%CVE-2025-37097HIGHA vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of serviceEPSS 0.5%CVE-2022-46156HIGHGrafana's default installation of `synthetic-monitoring-agent` exposes sensitive informationEPSS 0.5%CVE-2021-33639HIGHREMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.EPSS 0.5%CVE-2026-48056CRITICALStreambert Vulnerable to Arbitrary Binary Execution via Downloader IPC HandlerEPSS 0.5%CVE-2025-14713HIGHAn Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote atEPSS 0.5%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.5%CVE-2023-3655HIGHUnauthenticated Remote Database ExfiltrationEPSS 0.5%CVE-2020-12912A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power LEPSS 0.5%CVE-2024-47005HIGHSharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficientEPSS 0.5%CVE-2026-61793MEDIUMNuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameterEPSS 0.5%CVE-2026-30797CRITICALRustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled ServerEPSS 0.5%CVE-2026-18901HIGHH3C NX15 Web API esps service.add routineEPSS 0.5%CVE-2025-5748HIGHWOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-30921CRITICALOneUptime Synthetic Monitor RCE via exposed Playwright browser objectEPSS 0.4%CVE-2026-2275CRITICALCVE-2026-2275EPSS 0.4%CVE-2025-53964CRITICALGoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary andEPSS 0.4%