Threats Tagged 'cwe-749'
View all threats tagged with 'cwe-749'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-749'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-68823: CWE-749: Exposed Dangerous Method or Function in Microsoft Azure Confidential LedgerCVE-2026-68823 0 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Join the discussion | GCVE Database | 08/06/2026, 22:37:41 UTC Added: 08/07/2026, 05:56:42 UTC |
CVE-2026-68823: CWE-749: Exposed Dangerous Method or Function in Microsoft Azure Confidential LedgerCVE-2026-68823 0 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Join the discussion | CVE Database V5 | 08/06/2026, 22:37:41 UTC Added: 08/07/2026, 00:27:03 UTC |
CVE-2026-20467: CWE-749 Exposed Dangerous Method or Function in MediaTek, Inc. MediaTek chipsetCVE-2026-20467 0 In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767. Join the discussion | CVE Database V5 | 08/03/2026, 02:05:18 UTC Added: 08/03/2026, 02:48:33 UTC |
CVE-2026-44107: CWE-749 Exposed Dangerous Method or Function in Phoenix Contact CHARX SEC-3150CVE-2026-44107 0 CVE-2026-44107 is a high-severity vulnerability in the Phoenix Contact CHARX SEC-3150 charging controller. It allows an unauthenticated attacker to trigger a reboot of the device via Modbus TCP when the Modbus service is enabled. This results in a denial-of-service (DoS) condition by disrupting the charging controller's operation. Join the discussion | CVE Database V5 | 07/30/2026, 06:53:28 UTC Added: 07/30/2026, 07:22:40 UTC |
CVE-2026-53633: CWE-749: Exposed Dangerous Method or Function in vitest-dev vitestCVE-2026-53633 0 Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta. Join the discussion | CVE Database V5 | 07/14/2026, 19:35:42 UTC Added: 07/14/2026, 20:03:53 UTC |
CVE-2026-45489: CWE-749: Exposed Dangerous Method or Function in Microsoft Microsoft Edge (Chromium-based)CVE-2026-45489 0 CVE-2026-45489 is a medium severity spoofing vulnerability in Microsoft Edge (Chromium-based) involving an exposed dangerous method or function. The vulnerability allows an attacker to potentially spoof content, impacting confidentiality but not integrity or availability. An official fix is available from Microsoft. Join the discussion | GCVE Database | 07/03/2026, 20:35:36 UTC Added: 07/13/2026, 09:21:32 UTC |
Showing 1 to 6 of 6 results