boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-942

Weakness type CWE-942 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
33320

Monthly trend

▂▁▁▁▁▁▅▆█▅

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 12 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-547535.954.2Nx: `nx graph` dev server permissive CORS policy
CVE-2026-560768.651.9PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authen…
CVE-2026-5972610.039.4Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVE-2025-434808.138.1
CVE-2026-448959.232.5GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all …
CVE-2026-464099.629.5OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
CVE-2026-542907.125.8Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to th…
CVE-2026-653107.524.7Missing authentication and permissive CORS policy
CVE-2026-617369.323.2LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-89197.222.7
CVE-2026-748817.120.6openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins
CVE-2026-97399.420.5
CVE-2026-623877.117.8Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin
CVE-2026-685176.517.5Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — …
CVE-2026-579572.316.6Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint
CVE-2026-100567.515.6CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-ori…
CVE-2026-466087.414.4Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom…
CVE-2026-186765.114.1Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS w…
CVE-2026-464314.312.7Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVE-2026-500884.712.2Aqara Developer Portal cross-origin resource sharing

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
hclsoftware3
aqara2
getgrav2
nicolargo2
andritz1
apple1
asus1
electron1
google1
hkuds1
honojs1
ibm1
jahlives1
janhq1
kong1