VulnSea

CWE-1385

CVEs classified under CWE-1385, newest first.

10 CVEsRSS

CVE-2026-54565Medium· 4.7
5d ago

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages,…

Sunlitedwardkim · rhwpEPSS 0.13%via NVD
CVE-2026-13272Medium· 5.4
1w ago

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

SunlitIBM · Verify Identity AccessEPSS 0.15%via NVD
CVE-2026-18251Medium· 4.3
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

SunlitIBM · iEPSS 0.14%via NVD
CVE-2026-71416High· 8.8PoC
1w ago

Headroom compresses data before the data reaches a large language model

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to …

Midnightheadroomlabs-ai · headroomEPSS 0.17%via NVD
CVE-2026-88061Medium· 5.8
1w ago

career-ops is an open-source AI-assisted job search and application management tool

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or …

Sunlitsantifer · career-opsEPSS 0.24%via NVD
CVE-2026-85183Critical· 9.3
2w ago

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitra…

MidnightEPSS 0.15%via NVD
CVE-2026-15580None
1mo ago

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.

SunlitEPSS 0.19%via NVD
CVE-2026-59950High
2mo ago

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

Twilightmcp · mcpEPSS 0.23%via OSV
CVE-2026-10054High· 8.8
2mo ago

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin va…

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin va…

TwilightEPSS 0.22%via NVD
CVE-2026-1692Medium· 6.1
6mo ago

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote at…

Sunlitarcinfo · pcvueEPSS 0.11%via NVD
CWE-1385 vulnerabilities (CVEs) · VulnSea