CWE · MITRE source
CWE-749Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
This weakness can lead to a wide variety of resultant weaknesses, depending on the behavior of the exposed method. It can apply to any number of technologies and approaches, such as ActiveX controls, Java functions, IOCTLs, and so on. The exposure can occur in a few different ways:
Last updated: 20 August 2026 20:22 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 5 mapping(s) from 3 framework(s): STIG ubuntu 22 04 3 (mostly) · CAPEC 1 (partial) · STIG ubuntu 24 04 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (2)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
CM-7 | Least Functionality | CM | Explicitly prohibiting dangerous or unnecessary functions and services prevents exposure of methods that could be directly exploited. |
SC-25 | Thin Nodes | SC | Minimal functionality removes or avoids exposure of dangerous methods and functions. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2018-10931 UPD | 9.8 | 9.8 | 0.6786 | 2018-08-09 |
CVE-2023-51573 UPD | 9.2 | 9.8 | 0.4574 | 2024-04-01 |
CVE-2021-34996 UPD | 9.1 | 8.8 | 0.8226 | 2022-01-13 |
CVE-2023-38124 UPD | 8.8 | 8.8 | 0.5961 | 2024-05-03 |
CVE-2006-1547 KEV UPD | 8.5 | 7.5 | 0.5464 | 2006-03-30 |
CVE-2010-1428 KEV UPD | 8.5 | 7.5 | 0.6231 | 2010-04-28 |
CVE-2018-19322 KEV UPD | 8.5 | 7.8 | 0.0187 | 2018-12-21 |
CVE-2021-28809 UPD | 8.4 | 9.8 | 0.1580 | 2021-07-08 |
CVE-2020-15623 UPD | 8.1 | 9.8 | 0.0833 | 2020-07-28 |
CVE-2021-42128 UPD | 7.9 | 9.8 | 0.0450 | 2021-12-07 |
CVE-2023-27363 UPD | 7.8 | 7.8 | 0.4699 | 2024-05-03 |
CVE-2023-44414 UPD | 7.7 | 9.8 | 0.0235 | 2024-05-03 |
CVE-2026-22812 UPD | 7.7 | 8.8 | 0.1697 | 2026-01-12 |
CVE-2020-8212 UPD | 7.6 | 9.8 | 0.0164 | 2020-08-17 |
CVE-2023-40151 UPD | 7.6 | 10.0 | 0.0115 | 2023-11-21 |
CVE-2023-40500 UPD | 7.6 | 9.8 | 0.0148 | 2024-05-03 |
CVE-2023-40501 UPD | 7.6 | 9.8 | 0.0148 | 2024-05-03 |
CVE-2023-51574 UPD | 7.6 | 9.8 | 0.0155 | 2024-05-03 |
CVE-2023-51575 UPD | 7.6 | 9.8 | 0.0148 | 2024-05-03 |
CVE-2023-51581 UPD | 7.6 | 9.8 | 0.0148 | 2024-05-03 |
CVE-2023-51582 UPD | 7.6 | 9.8 | 0.0148 | 2024-05-03 |
CVE-2023-51583 UPD | 7.6 | 9.8 | 0.0148 | 2024-05-03 |
CVE-2010-0738 KEV UPD | 7.5 | 5.3 | 0.7942 | 2010-04-28 |
CVE-2022-4136 UPD | 7.5 | 9.8 | 0.0094 | 2022-11-24 |
CVE-2023-40150 UPD | 7.5 | 9.8 | 0.0101 | 2023-09-11 |