Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-942 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 33 | 32 | 0 |
▂▁▁▁▁▁▅▆█▅
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 12 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-54753 | 5.9 | 54.2 | — | Nx: `nx graph` dev server permissive CORS policy |
| CVE-2026-56076 | 8.6 | 51.9 | — | PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authen… |
| CVE-2026-59726 | 10.0 | 39.4 | — | Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment |
| CVE-2025-43480 | 8.1 | 38.1 | — | — |
| CVE-2026-44895 | 9.2 | 32.5 | — | GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all … |
| CVE-2026-46409 | 9.6 | 29.5 | — | OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution |
| CVE-2026-54290 | 7.1 | 25.8 | — | Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to th… |
| CVE-2026-65310 | 7.5 | 24.7 | — | Missing authentication and permissive CORS policy |
| CVE-2026-61736 | 9.3 | 23.2 | — | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests |
| CVE-2026-8919 | 7.2 | 22.7 | — | — |
| CVE-2026-74881 | 7.1 | 20.6 | — | openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins |
| CVE-2026-9739 | 9.4 | 20.5 | — | — |
| CVE-2026-62387 | 7.1 | 17.8 | — | Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin |
| CVE-2026-68517 | 6.5 | 17.5 | — | Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — … |
| CVE-2026-57957 | 2.3 | 16.6 | — | Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint |
| CVE-2026-10056 | 7.5 | 15.6 | — | CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-ori… |
| CVE-2026-46608 | 7.4 | 14.4 | — | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom… |
| CVE-2026-18676 | 5.1 | 14.1 | — | Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS w… |
| CVE-2026-46431 | 4.3 | 12.7 | — | Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * |
| CVE-2026-50088 | 4.7 | 12.2 | — | Aqara Developer Portal cross-origin resource sharing |