The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
Volume of CVEs assigned to CWE-940 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-61932CRITICAL Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrar | Oct 20, 2025 | 9.8 | 76 | YES | NO |
CVE-2026-6734HIGH Impact:
When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requ | Jun 17, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-2611CRITICAL In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross | May 19, 2026 | 9.6 | 37 | NO | NO |
CVE-2026-44698HIGH Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion ap | May 29, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-48745CRITICAL Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted d | Jun 16, 2026 | 9.3 | 34 | NO | NO |
CVE-2026-55660HIGH Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass e | Jul 1, 2026 | 7.6 | 32 | NO | NO |
CVE-2026-44894HIGH Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior t | Jun 12, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-33875CRITICAL Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially a | Mar 27, 2026 | 9.3 | 32 | NO | NO |
CVE-2025-59159CRITICAL SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | Oct 6, 2025 | 9.6 | 32 | NO | NO |
CVE-2026-45245HIGH Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, c | May 18, 2026 | 7.4 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.