CWE-942: CWE-942
Yearly Trend
Top Affected Vendors
All CWE-942 CVEs (22)
This vulnerability allows attackers to bypass the same-origin policy in Firefox and Thunderbird by exploiting a flaw in the DOM Workers component. It ...
Nov 11, 2025This CVE describes a same-origin policy bypass vulnerability in the DOM Notifications component of Mozilla products. It allows malicious websites to a...
Nov 11, 2025A logic vulnerability in Casdoor's CORS filter allows any website to make cross-domain requests to Casdoor as the logged-in user. This occurs because ...
Aug 20, 2024CVE-2023-23464 is a permissive Flash cross-domain policy vulnerability in Media CP Media Control Panel that allows attackers to bypass same-origin pol...
Feb 15, 2023CVE-2024-37131 is an overly permissive Cross-Origin Resource Policy (CORP) vulnerability in Dell Secure Connect Gateway Policy Manager. This allows re...
Jun 13, 2024CVE-2023-2360 is a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Acronis Cyber Infrastructure that allows attackers to steal ...
Apr 28, 2023CVE-2022-47717 is a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Last Yard version 22.09.8-1 that allows malicious websites ...
Feb 1, 2023Litestar ASGI framework versions before 2.20.0 have a CORS origin validation bypass vulnerability. Attackers can craft malicious origin headers that m...
Feb 9, 2026Omnissa UAG contains a CORS bypass vulnerability that allows attackers with network access to circumvent administrator-configured CORS restrictions. T...
Apr 17, 2025This CVE describes an overly permissive CORS policy vulnerability in Siemens industrial software products. An attacker could exploit this by tricking ...
Dec 12, 2023This CVE describes an insecure CORS policy in Tenda W30E V2 routers that allows attacker-controlled websites to make authenticated cross-origin reques...
Jan 26, 2026A CORS misconfiguration in Eramba Community and Enterprise Editions allows malicious websites to perform authenticated cross-origin requests against t...
Jan 13, 2026This CVE describes a same-origin policy bypass vulnerability in the Layout component of Mozilla products. It allows malicious websites to access data ...
Sep 16, 2025CVE-2024-6449 is a cross-site scripting (XSS) vulnerability in HyperView Geoportal Toolkit that allows unauthenticated attackers to inject and execute...
Aug 28, 2024PILOS before version 4.8.0 has a CORS misconfiguration that reflects the Origin header without validation while allowing credentials. This could theor...
Oct 27, 2025This CVE describes a Cross-Site Scripting (XSS) vulnerability in Drupal Next.Js modules due to an overly permissive cross-domain security policy. Atta...
Jan 28, 2026IBM Concert Software versions 1.0.0 through 1.1.0 have an overly permissive CORS configuration that doesn't restrict allowed origins to trusted domain...
Aug 18, 2025IBM Aspera Faspex versions 5.0.0 through 5.0.13.1 have an overly permissive cross-domain policy file that includes untrusted domains. This could allow...
Oct 9, 2025IBM Security ReaQta 3.12 contains a cross-site scripting vulnerability that allows privileged users to inject malicious JavaScript into the web interf...
Nov 14, 2024This vulnerability allows malicious websites to bypass same-origin policy protections and exfiltrate image data from other websites. It affects users ...
Nov 4, 2025A sandbox bypass vulnerability in Bruno IDE allows malicious API collection files to execute arbitrary code when imported and run, even in Safe Mode. ...
Apr 1, 2025An incorrect CORS configuration in Hiberus Sintra allows attackers to perform cross-origin requests with credentials, potentially enabling unauthorize...
Oct 2, 2025About CWE-942 (CWE-942)
Our database tracks 22 CVEs classified as CWE-942, with 0 rated critical and 10 rated high severity. The average CVSS score for CWE-942 vulnerabilities is 6.6.
External reference: View CWE-942 on MITRE CWE →
Monitor CWE-942 Vulnerabilities
Get alerted when new CWE-942 CVEs affect your infrastructure.
Start Monitoring Free