VulnSea

CWE-940

CVEs classified under CWE-940, newest first.

9 CVEsRSS

CVE-2026-85125Medium· 5.4
1w ago

The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation

The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websi…

SunlitYAMAP INC. · YAMAP -Social Trekking GPS AppEPSS 0.19%via NVD
CVE-2026-89178High· 8.8
1w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing stude…

TwilightHowyar · WeenyGeniusEPSS 0.23%via NVD
CVE-2026-85085Critical· 9.6
2w ago

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

MidnightEPSS 0.22%via NVD
CVE-2026-73419Medium· 6.8
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound t…

Sunlitnextauthjs · next-authEPSS 0.19%via NVD
GHSA-x445-f3h2-j279Medium· 6.8
2mo ago

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

Sunlitauth · @auth/corevia GHSA
CVE-2026-55660High
3mo ago

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

Twilighttinacms · tinacmsEPSS 0.28%via GHSA
CVE-2026-6734High· 7.5
3mo ago

undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)

A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…

TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.34%via CSAF
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-44894High· 7.5
3mo ago

Netty's Default QUIC token handler accepts any client-supplied token

Netty's Default QUIC token handler accepts any client-supplied token

Twilightnetty · io.netty:netty-codec-classes-quicEPSS 0.14%via GHSA
CWE-940 vulnerabilities (CVEs) · VulnSea