Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1385 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 5 | 0 |
▃█▁
2026-06 1 · 2026-07 4 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-57111 | 7.5 | 19.2 | — | Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-… |
| CVE-2026-59804 | 7.6 | 11.9 | — | Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket |
| CVE-2026-44211 | 9.6 | 7.9 | — | Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability |
| CVE-2026-10054 | 8.8 | 5.6 | — | — |
| CVE-2026-59950 | 7.6 | 4.6 | — | MCP Python SDK: WebSocket server transport does not support Host/Origin validation |
| Vendor | CVEs |
|---|---|
| apache | 1 |
| cline | 1 |
| eclipse foundation | 1 |
| modelcontextprotocol | 1 |
| web-infra-dev | 1 |