boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-942

Weakness type CWE-942 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
48470

Monthly trend

▂▁▁▁▁▁▅▆█▇▇▂

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 12 · 2026-08 10 · 2026-09 10 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-5972610.087.0—Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
CVE-2026-844528.675.1—Windows ML CLI: CORS misconfig enables localhost RCE
CVE-2026-617369.372.0—LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-547535.967.2—Nx: `nx graph` dev server permissive CORS policy
CVE-2026-628958.855.6—Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
CVE-2026-560768.653.1—PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authen…
CVE-2026-448959.247.9—GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all …
CVE-2026-822918.144.2—HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials
CVE-2026-822878.641.6—Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials
CVE-2026-653107.540.7—Missing authentication and permissive CORS policy
CVE-2026-890587.438.9—Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wi…
CVE-2026-685176.537.6—Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — …
CVE-2025-434808.137.5——
CVE-2026-89197.236.7——
CVE-2026-908828.736.1—Reflected arbitrary origins with credentials, allowing cross-origin reads of authentica…
CVE-2026-579572.335.6—Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint
CVE-2026-660707.633.4—RabbitMQ: CORS * reflects Origin with Allow-Credentials
CVE-2026-466087.432.0—Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom…
CVE-2026-634078.229.2—Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses
CVE-2026-159669.829.0—Improper CORS handling in MOVEit Transfer

Most-affected vendors