VulnSea

CWE-346

CVEs classified under CWE-346, newest first.

110 CVEsRSS

CVE-2026-94111Medium· 6.6
yesterday

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicio…

SunlitTencent · BrowserSkillEPSS 0.10%via NVD
CVE-2026-92702Critical· 9.1
3d ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce att…

Midnightultravioletrs · cocosEPSS 0.21%via NVD
CVE-2026-92701Critical· 9.1PoC
3d ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expe…

Abyssalultravioletrs · cocosEPSS 0.22%via NVD
CVE-2026-77339Medium· 5.1PoC
3d ago

Process Compose is a scheduler and orchestrator for non-containerized applications

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating …

Twilightf1bonacc1 · github.com/f1bonacc1/process-composeEPSS 0.21%via NVD
CVE-2026-72702Low
4d ago

Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Sunlitgetgrav · getgrav/gravEPSS 0.10%via GHSA
CVE-2026-12284Low· 3.7
4d ago

Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an …

Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an …

SunlitMattermost · MattermostEPSS 0.13%via NVD
CVE-2026-75025Medium· 4.7
5d ago

Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources

Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this im…

SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-77119Medium· 5.9
5d ago

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

SunlitISC · BIND 9EPSS 0.19%via NVD
CVE-2026-19941Medium· 5.9
5d ago

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…

SunlitISC · BIND 9EPSS 0.19%via NVD
CVE-2026-92359Low· 3.1
5d ago

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipu…

Sunlitag-ui-protocol · ag-uiEPSS 0.23%via NVD
CVE-2026-92360Medium· 6.3
5d ago

A weakness has been identified in ag-ui-protocol ag-ui 1.0

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_STA…

Sunlitag-ui-protocol · ag-uiEPSS 0.18%via NVD
CVE-2026-86466High· 8.1
5d ago

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a …

Twilightapache · apache-airflow-providers-fabEPSS 0.36%via NVD
CVE-2026-92034Critical· 9.1
6d ago

Site isolation issue in the Graphics component

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-59971Critical· 10.0
6d ago

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_se…

Midnightdesigncomputer · mysql_mcp_serverEPSS 0.39%via NVD
CVE-2026-57112High· 8.3PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legac…

MidnightMervinPraison · PraisonAIEPSS 0.19%via NVD
CVE-2026-91201Medium· 5.4
1w ago

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window…

Sunlitarc53 · DocsGPTEPSS 0.14%via NVD
CVE-2026-23792Medium· 4.0
1w ago

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC …

SunlitSamsung · Exynos 1080 firmwareEPSS 0.13%via NVD
CVE-2026-82438High· 8.1
1w ago

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

TwilightApache Software Foundation · org.apache.storm:storm-webappEPSS 0.20%via NVD
CVE-2026-55837Medium· 6.8PoC
1w ago

dbt-mcp is a Model Context Protocol server for interacting with dbt

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user com…

Twilightdbt-labs · dbt-mcpEPSS 0.21%via NVD
CVE-2026-50025Medium· 6.9
1w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

Sunlitt-mart · mouseholeEPSS 0.18%via NVD
CVE-2026-87563Medium· 4.3⚖ disputed
1w ago

Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.16%via NVD
CVE-2026-69680High· 8.1
1w ago

Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.

Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.34%via NVD
CVE-2026-69559Medium· 5.8
1w ago

Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft Teams for AndroidEPSS 0.32%via NVD
CVE-2026-75156Critical· 9.1
1w ago

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth p…

Midnightapache · apache-airflow-providers-fabEPSS 0.27%via NVD
CVE-2026-58649Medium· 6.5
1w ago

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.27%via NVD
CVE-2026-85152High· 7.4
2w ago

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin s…

Twilightnodejs · undiciEPSS 0.16%via NVD
CVE-2026-84482High· 8.8
2w ago

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains…

TwilightEPSS 0.14%via NVD
CVE-2026-19418High
2w ago

TYPO3 CMS - Broken Access Control in Backend and Install Tool

TYPO3 CMS - Broken Access Control in Backend and Install Tool

Twilighttypo3 · typo3/cms-backendEPSS 0.21%via GHSA
CVE-2026-70309Medium· 5.4
3w ago

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.16%via CVEORG
CVE-2026-56854Medium· 6.8
3w ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)

A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.33%via CSAF
CWE-346 vulnerabilities (CVEs) · VulnSea