Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-749

MITRE ↗

CWE-749

11
CRITICAL
21
HIGH
14
MEDIUM
48 CVEs
10.0
CVE-2026-48056

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro

9.9
CVE-2026-30921

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allo

9.9
CVE-2026-30957

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allo

9.9
CVE-2026-41283

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha

9.9
CVE-2026-55454

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr

9.8
CVE-2026-24118

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability

9.8
CVE-2026-53633

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo

9.6
CVE-2026-22208

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil

9.6
CVE-2026-2275

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar

9.1
CVE-2025-53827

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi

9.1
CVE-2026-68823

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n

8.8
CVE-2026-22812

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP serv

8.8
CVE-2026-45805

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve

8.7
CVE-2026-33583

Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via a

8.5
CVE-2026-5173

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and

8.3
CVE-2026-44698

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for

8.3
CVE-2026-52877

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the op

8.1
CVE-2026-30797

Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, An

8.1
CVE-2026-35488

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Rec

7.8
CVE-2026-20423

In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca

7.8
CVE-2026-3483

An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei

7.8
CVE-2026-8108

The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.

7.8
CVE-2026-13121

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne

7.8
CVE-2026-18262

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne

7.8
CVE-2026-18263

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne

7.5
CVE-2026-28400

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e

7.5
CVE-2025-14713

An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0

7.5
CVE-2026-44107

A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f

7.2
CVE-2026-4051

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to e

7.2
CVE-2026-18901

A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e

7.1
CVE-2025-47366

Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.

7.1
CVE-2026-44798

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to

6.5
CVE-2026-8109

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen

6.5
CVE-2026-44836

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3

6.5
CVE-2026-12060

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticate

6.5
CVE-2026-45489

Microsoft Edge (Chromium-based) Spoofing Vulnerability

6.0
CVE-2026-20467

In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatio

5.9
CVE-2026-54753

Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H

5.7
CVE-2026-49993

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers

5.5
CVE-2026-25266

Memory corruption while processing IOCTL command when device is in power-save state.

5.4
CVE-2026-45670

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions

5.3
CVE-2026-6402

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving o

5.3
CVE-2026-33584

Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit

4.8
CVE-2026-48783

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept

4.7
CVE-2026-14620

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a

4.3
CVE-2026-7516

A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese mark

CVE-2025-9611

Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. Th

CVE-2026-47899

The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with

Frequently Asked Questions

What is CWE-749?

CWE-749 (CWE-749) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-749?

There are 48 CVE records associated with CWE-749 in our database. Of these, 11 are critical severity, 21 are high severity, and 14 are medium severity.

How can I protect against CWE-749 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-749 using AI-powered security agents.

Detect CWE-749 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-749 vulnerabilities across your infrastructure.

Get Started