CWE-942: CWE-942

22
Total CVEs
0
Critical
10
High
6.6
Avg CVSS

Yearly Trend

2026
4
2025
10
2024
4
2023
4

Top Affected Vendors

1 Ibm 3
2 Mozilla 3
3 Hyperview 1
4 Lastyard 1
5 Mediacp 1
6 Dell 1
7 Eramba 1
8 Tenda 1
9 Siemens 1
10 Apple 1

All CWE-942 CVEs (22)

CVE-2025-13019
8.1

This vulnerability allows attackers to bypass the same-origin policy in Firefox and Thunderbird by exploiting a flaw in the DOM Workers component. It ...

Nov 11, 2025
CVE-2025-13017
8.1

This CVE describes a same-origin policy bypass vulnerability in the DOM Notifications component of Mozilla products. It allows malicious websites to a...

Nov 11, 2025
CVE-2024-41657
8.1

A logic vulnerability in Casdoor's CORS filter allows any website to make cross-domain requests to Casdoor as the logged-in user. This occurs because ...

Aug 20, 2024
CVE-2023-23464
8.1

CVE-2023-23464 is a permissive Flash cross-domain policy vulnerability in Media CP Media Control Panel that allows attackers to bypass same-origin pol...

Feb 15, 2023
CVE-2024-37131
7.5

CVE-2024-37131 is an overly permissive Cross-Origin Resource Policy (CORP) vulnerability in Dell Secure Connect Gateway Policy Manager. This allows re...

Jun 13, 2024
CVE-2023-2360
7.5

CVE-2023-2360 is a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Acronis Cyber Infrastructure that allows attackers to steal ...

Apr 28, 2023
CVE-2022-47717
7.5

CVE-2022-47717 is a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Last Yard version 22.09.8-1 that allows malicious websites ...

Feb 1, 2023
CVE-2026-25478
7.4

Litestar ASGI framework versions before 2.20.0 have a CORS origin validation bypass vulnerability. Attackers can craft malicious origin headers that m...

Feb 9, 2026
CVE-2025-25234
7.1

Omnissa UAG contains a CORS bypass vulnerability that allows attackers with network access to circumvent administrator-configured CORS restrictions. T...

Apr 17, 2025
CVE-2023-46281
7.1

This CVE describes an overly permissive CORS policy vulnerability in Siemens industrial software products. An attacker could exploit this by tricking ...

Dec 12, 2023
CVE-2026-24435
6.5

This CVE describes an insecure CORS policy in Tenda W30E V2 routers that allows attacker-controlled websites to make authenticated cross-origin reques...

Jan 26, 2026
CVE-2025-55462
6.5

A CORS misconfiguration in Eramba Community and Enterprise Editions allows malicious websites to perform authenticated cross-origin requests against t...

Jan 13, 2026
CVE-2025-10529
6.5

This CVE describes a same-origin policy bypass vulnerability in the Layout component of Mozilla products. It allows malicious websites to access data ...

Sep 16, 2025
CVE-2024-6449
6.5

CVE-2024-6449 is a cross-site scripting (XSS) vulnerability in HyperView Geoportal Toolkit that allows unauthenticated attackers to inject and execute...

Aug 28, 2024
CVE-2025-62523
6.3

PILOS before version 4.8.0 has a CORS misconfiguration that reflects the Origin header without validation while allowing credentials. This could theor...

Oct 27, 2025
CVE-2025-13984
6.1

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Drupal Next.Js modules due to an overly permissive cross-domain security policy. Atta...

Jan 28, 2026
CVE-2025-27909
5.4

IBM Concert Software versions 1.0.0 through 1.1.0 have an overly permissive CORS configuration that doesn't restrict allowed origins to trusted domain...

Aug 18, 2025
CVE-2023-37401
5.3

IBM Aspera Faspex versions 5.0.0 through 5.0.13.1 have an overly permissive cross-domain policy file that includes untrusted domains. This could allow...

Oct 9, 2025
CVE-2024-45642
5.3

IBM Security ReaQta 3.12 contains a cross-site scripting vulnerability that allows privileged users to inject malicious JavaScript into the web interf...

Nov 14, 2024
CVE-2025-43392
4.3

This vulnerability allows malicious websites to bypass same-origin policy protections and exfiltrate image data from other websites. It affects users ...

Nov 4, 2025
CVE-2025-30354
4.3

A sandbox bypass vulnerability in Bruno IDE allows malicious API collection files to execute arbitrary code when imported and run, even in Safe Mode. ...

Apr 1, 2025
CVE-2025-41010
N/A

An incorrect CORS configuration in Hiberus Sintra allows attackers to perform cross-origin requests with credentials, potentially enabling unauthorize...

Oct 2, 2025

About CWE-942 (CWE-942)

Our database tracks 22 CVEs classified as CWE-942, with 0 rated critical and 10 rated high severity. The average CVSS score for CWE-942 vulnerabilities is 6.6.

External reference: View CWE-942 on MITRE CWE →

Monitor CWE-942 Vulnerabilities

Get alerted when new CWE-942 CVEs affect your infrastructure.

Start Monitoring Free