Threats Tagged 'cwe-942'
View all threats tagged with 'cwe-942'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-942'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-65310: CWE-306 Missing authentication for critical function in ANDRITZ HIPASE-250CVE-2026-65310 0 ANDRITZ HIPASE-250, in its default configuration, exposes a data and configuration endpoint without any authentication and with permissive CORS settings. This allows an unauthenticated attacker with network access to read live process values and server configuration. The vulnerability is identified as CWE-306 (Missing Authentication for Critical Function) and CWE-942 (Permissive Cross-domain Whitelist). Join the discussion | CVE Database V5 | 07/31/2026, 07:26:29 UTC Added: 07/31/2026, 08:22:52 UTC |
CVE-2026-15966: CWE-942 Permissive cross-domain security policy with untrusted domains in Progress MOVEit TransferCVE-2026-15966 0 Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. Join the discussion | CVE Database V5 | 07/23/2026, 19:58:01 UTC Added: 07/23/2026, 20:22:51 UTC |
CVE-2024-23578: CWE-942 CWE-692: Incomplete Denial of Request to Insecure Resource in HCLSoftware Aftermarket EPCCVE-2024-23578 0 HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard). Join the discussion | CVE Database V5 | 07/17/2026, 13:50:08 UTC Added: 07/18/2026, 11:08:58 UTC |
CVE-2026-21761: CWE-942: Permissive Cross-Domain Policy with Untrusted Domains in HCLSoftware DevOps LoopCVE-2026-21761 0 HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. Join the discussion | CVE Database V5 | 07/17/2026, 17:10:02 UTC Added: 07/18/2026, 11:08:38 UTC |
CVE-2026-61736: CWE-942: Permissive Cross-domain Policy with Untrusted Domains in HKUDS LightRAGCVE-2026-61736 0 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. Any malicious website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating documents and knowledge graph data or performing destructive actions such as deleting the document store. This vulnerability is fixed in 1.5.4. Join the discussion | CVE Database V5 | 07/15/2026, 14:12:45 UTC Added: 07/15/2026, 14:48:48 UTC |
CVE-2026-8919: CWE-942: Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDKCVE-2026-8919 0 Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK ' section on the ASUS Security Advisory for more information. Join the discussion | CVE Database V5 | 07/15/2026, 02:00:46 UTC Added: 07/15/2026, 02:19:19 UTC |
Showing 1 to 6 of 6 results