Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-942

MITRE ↗

CWE-942

12
CRITICAL
44
HIGH
50
MEDIUM
5
LOW
125 CVEs · Page 3/3
6.8
CVE-2024-32862

Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

6.6
CVE-2023-45213

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could a

6.5
CVE-2023-37526

HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnera

6.5
CVE-2024-6449

HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote co

5.3
CVE-2023-50940

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privi

5.3
CVE-2024-45642

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb

4.3
CVE-2024-21382

Microsoft Edge for Android Information Disclosure Vulnerability

4.2
CVE-2024-23823

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le

CVE-2024-10315

In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD

CVE-2024-49763

PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensiti

CVE-2024-53276

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a

8.1
CVE-2023-23464

Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.

8.0
CVE-2023-46098

A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from

7.5
CVE-2022-47717

Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).

7.5
CVE-2023-2360

Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infras

7.1
CVE-2023-46281

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versi

6.8
CVE-2023-36829

Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2,

6.5
CVE-2022-34366

Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerabili

6.1
CVE-2023-23128

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that

5.4
CVE-2023-25603

A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.

9.8
CVE-2022-31736

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerabi

9.8
CVE-2022-26969

In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.

4.6
CVE-2021-27786

Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This requ

8.8
CVE-2021-34435

In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside th

6.5
CVE-2019-14860

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker

Frequently Asked Questions

What is CWE-942?

CWE-942 (CWE-942) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-942?

There are 125 CVE records associated with CWE-942 in our database. Of these, 12 are critical severity, 44 are high severity, and 50 are medium severity.

How can I protect against CWE-942 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-942 using AI-powered security agents.

Detect CWE-942 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-942 vulnerabilities across your infrastructure.

Get Started