Threats Tagged 'cwe-940'
View all threats tagged with 'cwe-940'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-940'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-102117 is a high-severity vulnerability in Kiteworks Core affecting versions prior to 9.5.1. It allows an authenticated System Administrator with access to a key protecting submitted data to redirect the system's outbound support connection to an attacker-controlled destination. This redirection can lead to remote code execution with the privileges of a local service account. Join the discussion | CVE Database V5 | 09/30/2026, 20:19:02 UTC Added: 09/30/2026, 20:34:21 UTC |
0 Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host. Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response. Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items. This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it. Join the discussion | CVE Database V5 | 09/30/2026, 08:03:04 UTC Added: 09/30/2026, 08:35:07 UTC |
0 WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker. Join the discussion | CVE Database V5 | 09/11/2026, 07:36:25 UTC Added: 09/11/2026, 07:47:51 UTC |
0 Le-yan Medical Practice Management System version 2.4.2.8 contains a remote code execution vulnerability due to improper verification of the source of a communication channel. This flaw allows unauthenticated remote attackers to execute arbitrary operating system commands by delivering a crafted HTML page. The vulnerability is identified as CWE-940 and has a high severity with a CVSS score of 8.8. Join the discussion | CVE Database V5 | 08/25/2026, 02:05:09 UTC Added: 08/25/2026, 02:22:40 UTC |
0 NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider because the stored cookie is not verified against the callback provider's identity, including the provider ID, issuer, client ID, or redirect URI. In a multi-provider application that permits account linking while logged in, when one provider's authorization request is observable and a target provider callback can be satisfied without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the attacker persistent sign-in to the victim's account, while cross-site request forgery alone is insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32. Join the discussion | CVE Database V5 | 08/12/2026, 20:23:39 UTC Added: 08/12/2026, 20:41:44 UTC |
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in. Join the discussion | CVE Database V5 | 06/18/2026, 16:13:47 UTC Added: 06/18/2026, 16:36:21 UTC |
0 Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into the app's persistent configuration with no confirmation, notification, or visual indication. A single crafted link delivered via SMS, email, a webpage, or any installed app can therefore reconfigure the app the moment the victim taps it, with no special permissions required. As a result, an attacker can covertly redirect all of the victim's GPS telemetry to their own server at maximum precision and frequency, and the change persists across restarts. This gives the attacker continuous, real-time tracking of the victim's location. This issue has been fixed in version 9.7.20. Join the discussion | CVE Database V5 | 06/16/2026, 22:19:37 UTC Added: 06/16/2026, 22:30:16 UTC |
0 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and webkit.messageHandlers.getExternalAuth (alongside revokeExternalAuth and externalBus) on iOS. Two flaws expose the bridge to all frames (including cross-origin iframes) and unsanitized interpolation of the JavaScript callback identifier allows a cross-origin iframe rendered inside the Companion app to execute arbitrary JavaScript in the Home Assistant frontend's main-frame origin and exfiltrate the signed-in user's access token. This vulnerability is fixed in 2026.4.1 for iOS and 2026.4.4 for Android. Join the discussion | CVE Database V5 | 05/29/2026, 13:32:20 UTC Added: 05/29/2026, 13:48:38 UTC |
0 CVE-2026-43880 is a medium severity vulnerability in WWBN AVideo versions up to and including 29.0. The vulnerability exists in the objects/sendEmail.json.php endpoint, which allows unauthenticated attackers to send emails using the site's legitimate SMTP infrastructure. This endpoint is explicitly allow-listed as a public write action and requires no authentication or CSRF token. An attacker who solves a captcha can supply arbitrary recipient email addresses and cause the site to send emails that appear to come from the site's own domain, passing SPF, DKIM, and DMARC checks. This can facilitate targeted phishing and brand impersonation attacks. A fix has been committed but no official patch or vendor advisory is currently provided. Join the discussion | CVE Database V5 | 05/11/2026, 20:37:15 UTC Added: 05/12/2026, 01:50:01 UTC |
0 Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild. Join the discussion | CVE Database V5 | 05/01/2026, 16:02:03 UTC Added: 05/01/2026, 16:21:55 UTC |
Showing 1 to 10 of 24 results