VulnSea

CWE-942

CVEs classified under CWE-942, newest first.

29 CVEsRSS

CVE-2026-56595Low· 3.1
4d ago

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, en…

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, en…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.15%via NVD
CVE-2026-89058High· 7.4PoC
4d ago

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…

MidnightRed Hat · RESTEasyEPSS 0.42%via NVD
CVE-2026-92359Low· 3.1
6d ago

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipu…

Sunlitag-ui-protocol · ag-uiEPSS 0.23%via NVD
CVE-2026-82438High· 8.1
1w ago

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

TwilightApache Software Foundation · org.apache.storm:storm-webappEPSS 0.20%via NVD
CVE-2026-62895High· 8.8
2w ago

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · Azure Arc SQL Server ExtensionEPSS 0.72%via NVD
CVE-2026-12962Medium· 5.3
2w ago

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to th…

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to th…

SunlitASUS · Armoury CrateEPSS 0.36%via NVD
CVE-2026-84452High
2w ago

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…

Twilightwinml-cli · winml-cliEPSS 0.95%via NVD
CVE-2026-53649Critical· 9.6
2w ago

Joro is a web exploitation framework

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelis…

MidnightBishopFox · github.com/BishopFox/joroEPSS 0.21%via NVD
CVE-2026-82291High· 8.1
3w ago

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visit…

TwilightEPSS 0.30%via NVD
CVE-2026-63407High· 8.2
1mo ago

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for…

TwilightEPSS 0.27%via NVD
CVE-2026-74881Medium· 6.5⚖ disputed
1mo ago

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of …

Sunlitjahlives · openssl_encryptEPSS 0.25%via NVD
CVE-2026-68517Medium· 6.5
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list conta…

Sunlitglances · glancesEPSS 0.33%via NVD
CVE-2026-46409Critical· 9.6
1mo ago

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without ser…

MidnightEPSS 0.36%via NVD
CVE-2026-70604High· 7.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was…

Twilightelectron · electronEPSS 0.28%via NVD
CVE-2026-65310High· 7.5
1mo ago

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with ne…

TwilightEPSS 0.32%via NVD
CVE-2026-54753Medium· 5.9
1mo ago

`nx graph` dev server permissive CORS policy

`nx graph` dev server permissive CORS policy

Sunlitnx · nxEPSS 1.2%via GHSA
CVE-2026-66005Medium· 6.3PoC
2mo ago

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…

Twilightjanhq · janEPSS 0.20%via NVD
CVE-2026-61736Critical· 9.3PoC
2mo ago

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

Abyssallightrag-hku · lightrag-hkuEPSS 1.4%via GHSA
CVE-2026-8919High· 7.2
2mo ago

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the a…

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the a…

TwilightASUS · GameSDKEPSS 0.45%via NVD
CVE-2026-53656Medium· 6.3
2mo ago

FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data

FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data

Sunlitfiftyone · fiftyoneEPSS 0.09%via GHSA
CVE-2026-59148High· 8.8PoC
2mo ago

Mockoon provides way to design and run mock APIs

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runti…

Midnightmockoon · mockoonEPSS 0.26%via NVD
CVE-2026-46608High· 7.4
3mo ago

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Twilightglances · glancesEPSS 0.40%via GHSA
CVE-2026-54290High· 7.1
3mo ago

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

Twilighthono · honoEPSS 0.33%via GHSA
CVE-2026-34449Critical· 9.6
5mo ago

SiYuan is a personal knowledge management system

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * …

Midnightb3log · siyuanEPSS 0.50%via NVD
CVE-2026-0397Low· 3.1
5mo ago

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the …

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the …

Sunlitpowerdns · dnsdistEPSS 0.16%via NVD
CVE-2026-34200High· 7.5PoC
5mo ago

Nhost is an open source Firebase alternative with GraphQL

Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. Thi…

Midnightnhost · cliEPSS 0.36%via NVD
CVE-2026-34237Medium· 6.1
5mo ago

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 0.83.0, 1.0.1, an…

Sunlitlfprojects · mcp_java_sdkEPSS 0.22%via NVD
CVE-2026-34227High· 8.8PoC
5mo ago

Sliver is a command and control framework that uses a custom Wireguard netstack

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beaco…

Midnightbishopfox · sliverEPSS 0.40%via NVD
CVE-2024-22348Medium· 5.3
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is n…

Sunlithcltech · devops_velocityEPSS 0.36%via NVD
CWE-942 vulnerabilities (CVEs) · VulnSea