Threats Tagged 'cwe-749'
View all threats tagged with 'cwe-749'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-749'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-55454: CWE-749: Exposed Dangerous Method or Function in appsmithorg appsmithCVE-2026-55454 0 Appsmith versions prior to 2.1 include a bundled Caddy reverse-proxy with an unauthenticated admin API bound to 0.0.0.0:2019 inside the container. Although this port is not exposed to the host by default, it is accessible from the Appsmith server process or via SSRF vulnerabilities. An authenticated low-privileged user can exploit this to fully replace the live Caddy configuration, effectively taking over the reverse proxy. This critical vulnerability is fixed in version 2.1. Join the discussion | CVE Database V5 | 06/24/2026, 21:38:07 UTC Added: 06/24/2026, 21:46:06 UTC |
CVE-2026-48783: CWE-345: Insufficient Verification of Data Authenticity in gitroomhq postiz-appCVE-2026-48783 0 Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint, /public/modify-subscription, could not change the persisted subscription tier, but it did execute enforcement-related side effects on the caller's own organization, including adjusting team-member enablement state, disabling integrations exceeding the asserted plan's limits, and resetting the scheduled-post cron when the asserted plan was the free tier. Impact is limited to the attacker's own organization and cannot be redirected at other tenants through this endpoint. This issue has been fixed in version 2.21.8. Join the discussion | CVE Database V5 | 06/16/2026, 21:38:00 UTC Added: 06/16/2026, 22:01:12 UTC |
CVE-2026-12060: CWE-749 Exposed dangerous method or function in Hepta Platforms HeptabaseCVE-2026-12060 0 Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions. Join the discussion | CVE Database V5 | 06/12/2026, 06:43:35 UTC Added: 06/12/2026, 08:48:31 UTC |
CVE-2026-7516: CWE-749: Exposed Dangerous Method or FunctionCVE-2026-7516 0 A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents. Join the discussion | CVE Database V5 | 06/10/2026, 14:08:47 UTC Added: 06/10/2026, 14:50:22 UTC |
CVE-2024-12651: CWE-749 Exposed Dangerous Method or Function in PTT Inc. HGS Mobile AppCVE-2024-12651 0 Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variables. This issue affects HGS Mobile App: before 6.5.0. Join the discussion | CVE Database V5 | 02/14/2025, 13:24:13 UTC Added: 06/01/2026, 15:03:54 UTC |
CVE-2026-44698: CWE-94: Improper Control of Generation of Code ('Code Injection') in home-assistant coreCVE-2026-44698 0 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation of the JavaScript callback identifier allows a cross-origin iframe rendered inside the Companion app to execute arbitrary JavaScript in the Home Assistant frontend's main-frame origin and exfiltrate the signed-in user's access token. This vulnerability is fixed in 2026.4.1 for iOS and 2026.4.4 for Android. Join the discussion | CVE Database V5 | 05/29/2026, 13:32:20 UTC Added: 05/29/2026, 13:48:38 UTC |
CVE-2026-44836: CWE-749: Exposed Dangerous Method or Function in ViewComponent view_componentCVE-2026-44836 0 A vulnerability in the view_component Ruby on Rails framework versions 3.0.0 through 4.8.x allows route access to inherited public methods on ViewComponent::Preview due to insufficient validation of preview example method names. This enables attackers to invoke methods like render_with_template with parameters from the request, potentially rendering internal Rails templates that are not normally accessible. The issue is fixed starting in version 4.9.0. Join the discussion | CVE Database V5 | 05/26/2026, 19:43:58 UTC Added: 05/26/2026, 20:35:41 UTC |
CVE-2026-4051: CWE-749 Exposed Dangerous Method or Function in IBM Engineering Lifecycle ManagementCVE-2026-4051 0 IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted. Join the discussion | CVE Database V5 | 05/26/2026, 18:12:43 UTC Added: 05/26/2026, 19:03:06 UTC |
Showing 1 to 8 of 8 results