Cyber Resilience

CWE · MITRE source

CWE-749Exposed Dangerous Method or Function

Abstraction: Base · CVEs in our corpus: 186

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

This weakness can lead to a wide variety of resultant weaknesses, depending on the behavior of the exposed method. It can apply to any number of technologies and approaches, such as ActiveX controls, Java functions, IOCTLs, and so on. The exposure can occur in a few different ways:

Last updated: 20 August 2026 20:22 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 5 mapping(s) from 3 framework(s): STIG ubuntu 22 04 3 (mostly) · CAPEC 1 (partial) · STIG ubuntu 24 04 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A01:2025 Broken Access Control.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • CM-7 Least Functionality
  • SC-25 Thin Nodes
  • PR.AA-05
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 4 hardening rules · 2 OS baselines
Validate
Prove the fix (OWASP ASVS)
  • V8.2.1

NIST 800-53 r5 controls that address this weakness (2)AI-assisted

Control Title Family Why it addresses this CWE
CM-7Least FunctionalityCMExplicitly prohibiting dangerous or unnecessary functions and services prevents exposure of methods that could be directly exploited.
SC-25Thin NodesSCMinimal functionality removes or avoids exposure of dangerous methods and functions.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2018-10931 9.89.80.67862018-08-09
CVE-2023-51573 9.29.80.45742024-04-01
CVE-2021-34996 9.18.80.82262022-01-13
CVE-2023-38124 8.88.80.59612024-05-03
CVE-2006-1547 KEV 8.57.50.54642006-03-30
CVE-2010-1428 KEV 8.57.50.62312010-04-28
CVE-2018-19322 KEV 8.57.80.01872018-12-21
CVE-2021-28809 8.49.80.15802021-07-08
CVE-2020-15623 8.19.80.08332020-07-28
CVE-2021-42128 7.99.80.04502021-12-07
CVE-2023-27363 7.87.80.46992024-05-03
CVE-2023-44414 7.79.80.02352024-05-03
CVE-2026-22812 7.78.80.16972026-01-12
CVE-2020-8212 7.69.80.01642020-08-17
CVE-2023-40151 7.610.00.01152023-11-21
CVE-2023-40500 7.69.80.01482024-05-03
CVE-2023-40501 7.69.80.01482024-05-03
CVE-2023-51574 7.69.80.01552024-05-03
CVE-2023-51575 7.69.80.01482024-05-03
CVE-2023-51581 7.69.80.01482024-05-03
CVE-2023-51582 7.69.80.01482024-05-03
CVE-2023-51583 7.69.80.01482024-05-03
CVE-2010-0738 KEV 7.55.30.79422010-04-28
CVE-2022-4136 7.59.80.00942022-11-24
CVE-2023-40150 7.59.80.01012023-09-11