Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1385
Weakness type CWE-1385 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 13 | 0 |
Monthly trend
▂▅▂█▁
2026-06 1 · 2026-07 4 · 2026-08 1 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-88061 | 5.8 | 29.1 | — | career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowi… |
| CVE-2026-57111 | 7.5 | 26.0 | — | Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-… |
| CVE-2026-59804 | 7.6 | 21.4 | — | Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket |
| CVE-2026-85183 | 9.3 | 13.0 | — | Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS |
| CVE-2026-59950 | 7.6 | 12.6 | — | MCP Python SDK: WebSocket server transport does not support Host/Origin validation |
| CVE-2026-10054 | 8.8 | 11.3 | — | — |
| CVE-2026-71416 | 8.8 | 11.3 | — | Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) |
| CVE-2026-44211 | 9.6 | 9.8 | — | Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability |
| CVE-2026-54565 | 4.7 | 8.0 | — | rhwp browser extension performs SSRF / private-network requests and leaks HWP preview d… |
| CVE-2026-15580 | 6.9 | 7.8 | — | PassPortal browser extension: vault token disclosure via unvalidated postMessage |
| CVE-2026-13272 | 5.4 | 3.5 | — | Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Secu… |
| CVE-2026-18251 | 4.3 | 2.8 | — | IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificat… |
| CVE-2026-67405 | 5.3 | 1.9 | — | RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 2 |
| apache | 1 |
| avaiga | 1 |
| cline | 1 |
| eclipse foundation | 1 |
| edwardkim | 1 |
| headroomlabs-ai | 1 |
| modelcontextprotocol | 1 |
| n-able | 1 |
| rabbitmq | 1 |
| santifer | 1 |
| web-infra-dev | 1 |