CWE-942 · 94 записей
Permissive Cross-domain Security Policy with Untrusted Domains
CVE этого класса
94 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-31736Эксплойта нет | A malicious website could have learned the size of a cross-origin resource that supported Range requests.mozilla · firefox · CWE-942 | Критическая9,8 | — | 1,1 % | 22 дек. 2022 г. |
39Наблюдать | CVE-2022-26969Эксплойта нет | In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.monospace · directus · CWE-942 | Критическая9,8 | — | 0,9 % | 26 дек. 2022 г. |
39Наблюдать | CVE-2021-27786Эксплойта нет | HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trustedhcltech · onetest server · CWE-942 | Критическая9,8 | — | 0,6 % | 9 июн. 2022 г. |
39Наблюдать | CVE-2024-37131Эксплойта нет | SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability.dell · policy manager for secure connect gateway · CWE-942 | Критическая9,8 | — | 0,5 % | 13 июн. 2024 г. |
39Наблюдать | CVE-2023-50940Эксплойта нет | IBM PowerSC cross-resource origin sharingibm · powersc · CWE-942 | Критическая9,8 | — | 0,5 % | 1 февр. 2024 г. |
39Наблюдать | CVE-2026-15966Эксплойта нет | Improper CORS handling in MOVEit Transferprogress · moveit transfer · CWE-942 | Критическая9,8 | — | 0,4 % | 23 июл. 2026 г. |
39Наблюдать | CVE-2025-61163Эксплойта нет | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains.CWE-942 | Критическая9,8 | — | 0,3 % | 26 авг. 2026 г. |
39Наблюдать | CVE-2025-27909Эксплойта нет | IBM Concert Software cross-origin resource sharingibm · concert · CWE-942 | Критическая9,8 | — | 0,2 % | 18 авг. 2025 г. |
38Наблюдать | CVE-2026-34449Эксплойта нет | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionb3log · siyuan · CWE-942 | Критическая9,6 | — | 0,8 % | 31 мар. 2026 г. |
37Наблюдать | CVE-2026-61736Proof of concept | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requestshkuds · lightrag · CWE-942 | Критическая9,3 | — | 1,4 % | 15 июл. 2026 г. |
37Наблюдать | CVE-2026-9739Эксплойта нет | Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790).google · mcp toolbox for databases · CWE-942 | Критическая9,4 | — | 0,2 % | 27 мая 2026 г. |
36Наблюдать | CVE-2026-8948Эксплойта нет | Same-origin policy bypass in the DOM: Networking componentmozilla · firefox · CWE-942 | Критическая9,1 | — | 0,5 % | 19 мая 2026 г. |
36Наблюдать | CVE-2026-30924Эксплойта нет | qui CORS Misconfiguration: Arbitrary Origins Trustedgetqui · qui · CWE-942 | Критическая9,0 | — | 0,4 % | 19 мар. 2026 г. |
36Наблюдать | CVE-2023-25603Эксплойта нет | A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.fortinet · fortiadc · CWE-942 | Критическая9,1 | — | 0,4 % | 14 нояб. 2023 г. |
35Наблюдать | CVE-2023-38125Эксплойта нет | Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerabilitysofting · edgeaggregator · CWE-942 | Высокая8,8 | — | 1,3 % | 2 мая 2024 г. |
35Наблюдать | CVE-2023-46281Эксплойта нет | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIsiemens · opcenter quality · CWE-942 | Высокая8,8 | — | 0,9 % | 12 дек. 2023 г. |
35Наблюдать | CVE-2024-41657Эксплойта нет | GHSL-2024-035: Casdoor CORS misconfigurationcasbin · casdoor · CWE-942 | Высокая8,8 | — | 0,8 % | 20 авг. 2024 г. |
35Наблюдать | CVE-2023-46098Эксплойта нет | A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1).siemens · simatic pcs neo · CWE-942 | Высокая8,8 | — | 0,6 % | 14 нояб. 2023 г. |
35Наблюдать | CVE-2021-34435Эксплойта нет | In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE.eclipse · theia · CWE-942 | Высокая8,8 | — | 0,6 % | 1 сент. 2021 г. |
35Наблюдать | CVE-2026-33010Эксплойта нет | mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theftdoobidoo · mcp-memory-service · CWE-942 | Высокая8,8 | — | 0,5 % | 20 мар. 2026 г. |
34Наблюдать | CVE-2026-56076Эксплойта нет | PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpointpraisonai · praisonai · CWE-942 | Высокая8,6 | — | 0,7 % | 18 июн. 2026 г. |
34Наблюдать | CVE-2024-49763Эксплойта нет | PlexRipper allows API leak due to open CORS policyplexripper · plexripper · CWE-942 | Высокая8,7 | — | 0,5 % | 2 дек. 2024 г. |
34Наблюдать | CVE-2026-82287Эксплойта нет | Rybbit Reflects Any Origin in CORS Responses While Allowing Credentialsrybbit-io · rybbit · CWE-942 | Высокая8,6 | — | 0,5 % | 28 авг. 2026 г. |
34Наблюдать | CVE-2026-90882Эксплойта нет | Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user dataeclipse foundation · open-vsx.org · CWE-942 | Высокая8,7 | — | 0,4 % | 22 сент. 2026 г. |
34Наблюдать | CVE-2025-30354Эксплойта нет | Bruno ignores Safe-Mode in Asserts expressionsusebruno · bruno · CWE-942 | Высокая8,7 | — | 0,4 % | 1 апр. 2025 г. |
- CVE-2022-3173639Наблюдать
A malicious website could have learned the size of a cross-origin resource that supported Range requests.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox22 дек. 2022 г.
- CVE-2022-2696939Наблюдать
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %monospace · directus26 дек. 2022 г.
- CVE-2021-2778639Наблюдать
HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trusted
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hcltech · onetest server9 июн. 2022 г.
- CVE-2024-3713139Наблюдать
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %dell · policy manager for secure connect gateway13 июн. 2024 г.
- CVE-2023-5094039Наблюдать
IBM PowerSC cross-resource origin sharing
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ibm · powersc1 февр. 2024 г.
- CVE-2026-1596639Наблюдать
Improper CORS handling in MOVEit Transfer
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %progress · moveit transfer23 июл. 2026 г.
- CVE-2025-6116339Наблюдать
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %26 авг. 2026 г.
- CVE-2025-2790939Наблюдать
IBM Concert Software cross-origin resource sharing
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ibm · concert18 авг. 2025 г.
- CVE-2026-3444938Наблюдать
SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %b3log · siyuan31 мар. 2026 г.
- CVE-2026-6173637Наблюдать
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
КритическаяCVSS 9,3Proof of conceptEPSS 1 %hkuds · lightrag15 июл. 2026 г.
- CVE-2026-973937Наблюдать
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790).
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %google · mcp toolbox for databases27 мая 2026 г.
- CVE-2026-894836Наблюдать
Same-origin policy bypass in the DOM: Networking component
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %mozilla · firefox19 мая 2026 г.
- CVE-2026-3092436Наблюдать
qui CORS Misconfiguration: Arbitrary Origins Trusted
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %getqui · qui19 мар. 2026 г.
- CVE-2023-2560336Наблюдать
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %fortinet · fortiadc14 нояб. 2023 г.
- CVE-2023-3812535Наблюдать
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %softing · edgeaggregator2 мая 2024 г.
- CVE-2023-4628135Наблюдать
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATI
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %siemens · opcenter quality12 дек. 2023 г.
- CVE-2024-4165735Наблюдать
GHSL-2024-035: Casdoor CORS misconfiguration
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %casbin · casdoor20 авг. 2024 г.
- CVE-2023-4609835Наблюдать
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %siemens · simatic pcs neo14 нояб. 2023 г.
- CVE-2021-3443535Наблюдать
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %eclipse · theia1 сент. 2021 г.
- CVE-2026-3301035Наблюдать
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %doobidoo · mcp-memory-service20 мар. 2026 г.
- CVE-2026-5607634Наблюдать
PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %praisonai · praisonai18 июн. 2026 г.
- CVE-2024-4976334Наблюдать
PlexRipper allows API leak due to open CORS policy
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %plexripper · plexripper2 дек. 2024 г.
- CVE-2026-8228734Наблюдать
Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %rybbit-io · rybbit28 авг. 2026 г.
- CVE-2026-9088234Наблюдать
Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %eclipse foundation · open-vsx.org22 сент. 2026 г.
- CVE-2025-3035434Наблюдать
Bruno ignores Safe-Mode in Asserts expressions
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %usebruno · bruno1 апр. 2025 г.