Known Vulnerabilities for Origin Client by Ea
Listed below are 1 of the newest known vulnerabilities associated with "Origin Client" by "Ea".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61451 json | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field i... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61448 json | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-61427 json | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option def... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-59804 json | Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration v... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59249 json | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious H... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-59214 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-58482 json | Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox`... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-56698 json | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open option, al... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-55767 json | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attrib... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-54458 json | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability ... | Not Provided | 2026-07-15 | 2026-07-16 |