Skip to main content

CWE archive

CWE-940 CVEs

Programmatic archive

55 CVEs tagged with CWE-94010 Critical, 18 High, 23 Medium, 4 Low, 0 Unrated.

CVE-2026-55660

Published Jul 1, 2026

Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-54106

Published Jun 18, 2026

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not v…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
32.6

CVE-2026-6734

Published Jun 17, 2026

Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All req…

CVSS 7.5 · High
evidence mentions
16
Buzz score
42.8
Vendor/product tagsBeta · best-effort

CVE-2026-48745

Published Jun 17, 2026

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-44894

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior…

CVSS 7.5 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-44698

Published May 29, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion a…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45353

Published May 28, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-2611

Published May 19, 2026

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cros…

CVSS 9.6 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-45245

Published May 18, 2026

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links,…

CVSS 4.6 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-43880

Published May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes two branches depending on whether contactForm=1 is submitted…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-23866

Published May 1, 2026

Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have all…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-40434

Published Apr 17, 2026

Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt application…

CVSS 8.1 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-35643

Published Apr 10, 2026

OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the can…

CVSS 8.6 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-33875

Published Mar 27, 2026

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2019-25613

Published Mar 22, 2026

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-2967

Published Feb 23, 2026

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Ha…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-22269

Published Feb 19, 2026

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privilege…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62439

Published Feb 10, 2026

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7…

CVSS 4.2 · Medium

CVE-2025-40820

Published Dec 9, 2025

Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within a broad range. This could allow an unauthenticated remote a…

CVSS 8.7 · High

CVE-2025-13086

Published Dec 3, 2025

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-32388

Published Dec 1, 2025

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61932

Published Oct 20, 2025

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitra…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-43280

Published Oct 15, 2025

The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59159

Published Oct 6, 2025

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice mode…

CVSS 9.6 · Critical

CVE-2025-20365

Published Sep 24, 2025

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 55 CVEsPage 1 of 3