Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allo
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allo
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo
OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil
The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP serv
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve
Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the op
Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, An
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Rec
In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei
The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne
Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to e
A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3
Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticate
Microsoft Edge (Chromium-based) Spoofing Vulnerability
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatio
Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers
Memory corruption while processing IOCTL command when device is in power-save state.
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions
webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving o
Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a
A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese mark
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. Th
The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with
Frequently Asked Questions
What is CWE-749?
CWE-749 (CWE-749) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-749?
There are 48 CVE records associated with CWE-749 in our database. Of these, 11 are critical severity, 21 are high severity, and 14 are medium severity.
How can I protect against CWE-749 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-749 using AI-powered security agents.
Detect CWE-749 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-749 vulnerabilities across your infrastructure.
Get Started