VulnSea

CWE-346

CVEs classified under CWE-346, newest first.

131 CVEsRSS

CVE-2026-46409Critical· 9.6
1mo ago

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without ser…

▾ MidnightEPSS 0.28%via NVD
CVE-2026-66732Medium· 5.9
1mo ago

Sonic 3 A.I.R

Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagr…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-47194None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point t…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-70599Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level …

▾ Sunlitelectron · electronEPSS 0.19%via NVD
CVE-2026-66318High· 8.1
1mo ago

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.36%via CVEORG
CVE-2026-66316Medium· 5.4
1mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.21%via CVEORG
CVE-2026-66313Medium· 6.8
1mo ago

Microsoft Edge (Chromium-based) Tampering Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.23%via CVEORG
CVE-2026-66317Medium· 5.4
1mo ago

Microsoft Edge (Chromium-based) Tampering Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.21%via CVEORG
CVE-2026-66322High· 7.1
1mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.23%via CVEORG
CVE-2026-69245Medium· 6.5
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.20%via NVD
CVE-2026-48063Critical
1mo ago

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…

▾ Midnightbaileys · baileysEPSS 0.22%via NVD
CVE-2026-66420High· 8.8
1mo ago

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the C…

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the C…

▾ TwilightYlianst · MeshCentralEPSS 0.22%via NVD
CVE-2026-63118Medium
1mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

▾ Sunlitmcp · mcpEPSS 0.26%via GHSA
CVE-2026-54605High· 7.2
2mo ago

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…

▾ Twilightoauth · oauthEPSS 0.19%via NVD
CVE-2026-57989High· 7.4
2mo ago

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.43%via NVD
CVE-2026-57978Medium· 5.4
2mo ago

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.21%via NVD
CVE-2026-16745High· 8.8
2mo ago

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI)

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbit…

▾ TwilightRed Hat · rhoai/odh-dashboard-rhel9EPSS 0.45%via NVD
GHSA-x445-f3h2-j279Medium· 6.8
2mo ago

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

▾ Sunlitauth · @auth/corevia GHSA
CVE-2026-59208High
2mo ago

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

▾ Twilightn8n · n8nEPSS 0.27%via GHSA
CVE-2023-49899Critical· 9.8
2mo ago

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

▾ MidnightEPSS 0.31%via NVD
CVE-2026-59950High
2mo ago

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

▾ Twilightmcp · mcpEPSS 0.23%via OSV
CVE-2026-53656Medium· 6.3
2mo ago

FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data

FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data

▾ Sunlitfiftyone · fiftyoneEPSS 0.12%via GHSA
CVE-2026-56181High· 8.3
2mo ago

Windows Network Address Translation (NAT) Spoofing Vulnerability

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.28%via CVEORG
CVE-2026-54069CriticalPoC
2mo ago

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via GHSA
CVE-2026-59883Medium· 4.7
2mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix m…

▾ Sunlitguzzlephp · guzzleEPSS 0.17%via NVD
CVE-2026-55438Medium· 5.8
2mo ago

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.22%via GHSA
CVE-2026-55487High· 7.5
3mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

▾ Twilightpnpm · pnpmEPSS 0.18%via GHSA
GHSA-9g5q-2w5x-hmxfHigh
3mo ago

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
CVE-2026-54665Medium· 5.3
3mo ago

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

▾ Sunlitapache · org.apache.nifi:nifi-jettyEPSS 0.33%via GHSA
CVE-2026-46611Medium· 5.3
3mo ago

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack

▾ Sunlitglances · glancesEPSS 0.17%via GHSA
CWE-346 vulnerabilities (CVEs) — page 3 · VulnSea