Skip to main content

CWE archive

CWE-1385 CVEs

Programmatic archive

34 CVEs tagged with CWE-13853 Critical, 13 High, 16 Medium, 2 Low, 0 Unrated.

CVE-2026-59950

Published Jul 15, 2026

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server trans…

CVSS 7.6 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-57111

Published Jul 9, 2026

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-59804

Published Jul 8, 2026

Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attack…

CVSS 7.6 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-10054

Published Jul 3, 2026

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) wit…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-44211

Published Jun 1, 2026

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanba…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44514

Published May 14, 2026

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on c…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-34403

Published Apr 20, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditio…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-35589

Published Apr 14, 2026

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/se…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27977

Published Mar 18, 2026

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal we…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-1692

Published Feb 26, 2026

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68930

Published Feb 23, 2026

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. Th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56647

Published Feb 12, 2026

npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server does not validate origin when connecting to a WebSocket clie…

CVSS 6.5 · Medium

CVE-2026-22689

Published Jan 10, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections from any origin. This lack of Or…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-21883

Published Jan 8, 2026

Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can r…

CVSS 4.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-61987

Published Dec 12, 2025

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user acce…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54289

Published Oct 2, 2025

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitra…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51775

Published Aug 3, 2025

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get inter…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36116

Published Jul 23, 2025

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52882

Published Jun 24, 2025

Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android S…

CVSS 8.8 · High

CVE-2025-48068

Published May 30, 2025

Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limit…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-8201

Published May 16, 2025

Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00;…

CVSS 5.4 · Medium

CVE-2025-24964

Published Feb 4, 2025

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is liste…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48849

Published Jan 29, 2025

Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <…

CVSS 8.8 · High

CVE-2025-24010

Published Jan 20, 2025

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23168

Published Aug 15, 2024

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

CVSS 9.8 · Critical
Showing 1-25 of 34 CVEsPage 1 of 2