Перейти к содержимому
Noroxi

CWE-942 · 94 записей

Permissive Cross-domain Security Policy with Untrusted Domains

CVE этого класса

94 записей

  • CVE-2022-31736
    39Наблюдать

    A malicious website could have learned the size of a cross-origin resource that supported Range requests.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mozilla · firefox22 дек. 2022 г.

  • CVE-2022-26969
    39Наблюдать

    In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    monospace · directus26 дек. 2022 г.

  • CVE-2021-27786
    39Наблюдать

    HCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin Trusted

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hcltech · onetest server9 июн. 2022 г.

  • CVE-2024-37131
    39Наблюдать

    SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    dell · policy manager for secure connect gateway13 июн. 2024 г.

  • CVE-2023-50940
    39Наблюдать

    IBM PowerSC cross-resource origin sharing

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    ibm · powersc1 февр. 2024 г.

  • CVE-2026-15966
    39Наблюдать

    Improper CORS handling in MOVEit Transfer

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    progress · moveit transfer23 июл. 2026 г.

  • CVE-2025-61163
    39Наблюдать

    Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    26 авг. 2026 г.

  • CVE-2025-27909
    39Наблюдать

    IBM Concert Software cross-origin resource sharing

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    ibm · concert18 авг. 2025 г.

  • CVE-2026-34449
    38Наблюдать

    SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    b3log · siyuan31 мар. 2026 г.

  • CVE-2026-61736
    37Наблюдать

    LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

    КритическаяCVSS 9,3Proof of conceptEPSS 1 %

    hkuds · lightrag15 июл. 2026 г.

  • CVE-2026-9739
    37Наблюдать

    Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790).

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    google · mcp toolbox for databases27 мая 2026 г.

  • CVE-2026-8948
    36Наблюдать

    Same-origin policy bypass in the DOM: Networking component

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    mozilla · firefox19 мая 2026 г.

  • CVE-2026-30924
    36Наблюдать

    qui CORS Misconfiguration: Arbitrary Origins Trusted

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    getqui · qui19 мар. 2026 г.

  • CVE-2023-25603
    36Наблюдать

    A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    fortinet · fortiadc14 нояб. 2023 г.

  • CVE-2023-38125
    35Наблюдать

    Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    softing · edgeaggregator2 мая 2024 г.

  • CVE-2023-46281
    35Наблюдать

    A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATI

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    siemens · opcenter quality12 дек. 2023 г.

  • CVE-2024-41657
    35Наблюдать

    GHSL-2024-035: Casdoor CORS misconfiguration

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    casbin · casdoor20 авг. 2024 г.

  • CVE-2023-46098
    35Наблюдать

    A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    siemens · simatic pcs neo14 нояб. 2023 г.

  • CVE-2021-34435
    35Наблюдать

    In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    eclipse · theia1 сент. 2021 г.

  • CVE-2026-33010
    35Наблюдать

    mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    doobidoo · mcp-memory-service20 мар. 2026 г.

  • CVE-2026-56076
    34Наблюдать

    PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    praisonai · praisonai18 июн. 2026 г.

  • CVE-2024-49763
    34Наблюдать

    PlexRipper allows API leak due to open CORS policy

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    plexripper · plexripper2 дек. 2024 г.

  • CVE-2026-82287
    34Наблюдать

    Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    rybbit-io · rybbit28 авг. 2026 г.

  • CVE-2026-90882
    34Наблюдать

    Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user data

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    eclipse foundation · open-vsx.org22 сент. 2026 г.

  • CVE-2025-30354
    34Наблюдать

    Bruno ignores Safe-Mode in Asserts expressions

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    usebruno · bruno1 апр. 2025 г.

Все классы уязвимостей