Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-942
Weakness type CWE-942 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 48 | 47 | 0 |
Monthly trend
▂▁▁▁▁▁▅▆█▇▇▂
2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 12 · 2026-08 10 · 2026-09 10 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-59726 | 10.0 | 87.0 | — | Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment |
| CVE-2026-84452 | 8.6 | 75.1 | — | Windows ML CLI: CORS misconfig enables localhost RCE |
| CVE-2026-61736 | 9.3 | 72.0 | — | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests |
| CVE-2026-54753 | 5.9 | 67.2 | — | Nx: `nx graph` dev server permissive CORS policy |
| CVE-2026-62895 | 8.8 | 55.6 | — | Azure Arc SQL Server Extension Elevation of Privilege Vulnerability |
| CVE-2026-56076 | 8.6 | 53.1 | — | PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authen… |
| CVE-2026-44895 | 9.2 | 47.9 | — | GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all … |
| CVE-2026-82291 | 8.1 | 44.2 | — | HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials |
| CVE-2026-82287 | 8.6 | 41.6 | — | Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials |
| CVE-2026-65310 | 7.5 | 40.7 | — | Missing authentication and permissive CORS policy |
| CVE-2026-89058 | 7.4 | 38.9 | — | Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wi… |
| CVE-2026-68517 | 6.5 | 37.6 | — | Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — … |
| CVE-2025-43480 | 8.1 | 37.5 | — | — |
| CVE-2026-8919 | 7.2 | 36.7 | — | — |
| CVE-2026-90882 | 8.7 | 36.1 | — | Reflected arbitrary origins with credentials, allowing cross-origin reads of authentica… |
| CVE-2026-57957 | 2.3 | 35.6 | — | Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint |
| CVE-2026-66070 | 7.6 | 33.4 | — | RabbitMQ: CORS * reflects Origin with Allow-Credentials |
| CVE-2026-46608 | 7.4 | 32.0 | — | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom… |
| CVE-2026-63407 | 8.2 | 29.2 | — | Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses |
| CVE-2026-15966 | 9.8 | 29.0 | — | Improper CORS handling in MOVEit Transfer |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| hclsoftware | 3 |
| aqara | 2 |
| asus | 2 |
| getgrav | 2 |
| hcl software | 2 |
| microsoft | 2 |
| nicolargo | 2 |
| ag-ui-protocol | 1 |
| andritz | 1 |
| apache | 1 |
| apple | 1 |
| bishopfox | 1 |
| eclipse foundation | 1 |
| electron | 1 |
| 1 |