Skip to main content

CWE archive

CWE-942 CVEs

Programmatic archive

114 CVEs tagged with CWE-94213 Critical, 43 High, 45 Medium, 13 Low, 0 Unrated.

CVE-2026-66005

Published Jul 24, 2026

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host re…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-15966

Published Jul 23, 2026

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 befor…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-21761

Published Jul 17, 2026

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially expos…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-23578

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62387

Published Jul 17, 2026

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-61736

Published Jul 15, 2026

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightr…

CVSS 9.3 · Critical
evidence mentions
6
Buzz score
24.5

CVE-2026-8919

Published Jul 15, 2026

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted we…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59148

Published Jul 9, 2026

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as use…

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-59726

Published Jul 9, 2026

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoint…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-56458

Published Jul 9, 2026

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12084

Published Jun 30, 2026

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions an…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57957

Published Jun 29, 2026

Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4

CVE-2026-54753

Published Jun 26, 2026

Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Or…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-46608

Published Jun 25, 2026

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-54290

Published Jun 22, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the C…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56076

Published Jun 18, 2026

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /ag…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-50088

Published Jun 12, 2026

The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an ins…

CVSS 8.2 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-50087

Published Jun 12, 2026

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untru…

CVSS 8.2 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-10056

Published May 29, 2026

CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unau…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46685

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflec…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45021

Published May 28, 2026

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp co…

CVSS 5.1 · Medium
evidence mentions
8
Buzz score
27.0

CVE-2026-9739

Published May 27, 2026

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP securi…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-44895

Published May 26, 2026

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-46431

Published May 26, 2026

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardle…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 114 CVEsPage 1 of 5