In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints.
Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 ar
Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject
Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for
Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an at
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vul
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke
Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes t
Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communicat
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file
Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po
Frequently Asked Questions
What is CWE-940?
CWE-940 (CWE-940) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-940?
There are 20 CVE records associated with CWE-940 in our database. Of these, 3 are critical severity, 9 are high severity, and 6 are medium severity.
How can I protect against CWE-940 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-940 using AI-powered security agents.
Detect CWE-940 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-940 vulnerabilities across your infrastructure.
Get Started