CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 4 of 13
- CVE-2021-21184MEDIUMCVSS 4.3EG 4.32021-03-09
Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21209MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21211MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21229MEDIUMCVSS 6.5EG 6.52021-04-30
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- CVE-2021-23986MEDIUMCVSS 6.5EG 6.52021-03-31
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origi…
- CVE-2021-26291CRITICALCVSS 9.1EG 9.12021-04-23
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert t…
- CVE-2021-26735MEDIUMCVSS 6.7EG 6.72023-10-23
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
- CVE-2021-26737MEDIUMCVSS 5.5EG 5.52023-10-23
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.
- CVE-2021-27197HIGHCVSS 8.1EG 8.12021-02-12
DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is trigg…
- CVE-2021-28048MEDIUMCVSS 6.5EG 6.52021-04-14
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-30596MEDIUMCVSS 4.3EG 4.32021-08-26
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-30630MEDIUMCVSS 4.3EG 4.32021-10-08
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
- CVE-2021-31718HIGHCVSS 8.8EG 8.82021-04-25
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
- CVE-2021-32985HIGHCVSS 7.2EG 7.22022-04-04
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.
- CVE-2021-33959HIGHCVSS 7.5EG 7.52023-01-18
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
- CVE-2021-34435HIGHCVSS 8.8EG 8.82021-09-01
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happen…
- CVE-2021-37705CRITICALCVSS 10.0EG 10.02021-08-13
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API call…
- CVE-2021-37966MEDIUMCVSS 4.3EG 4.32021-10-08
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-37967MEDIUMCVSS 4.3EG 4.32021-10-08
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
- CVE-2021-37971MEDIUMCVSS 4.3EG 4.32021-10-08
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2021-38497MEDIUMCVSS 6.5EG 6.52021-11-03
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < …
- CVE-2021-38507MEDIUMCVSS 6.5EG 6.52021-12-08
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port …
- CVE-2021-39063CRITICALCVSS 9.1EG 9.12021-12-13
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control head…
- CVE-2021-39175HIGHCVSS 8.1EG 8.12021-08-30
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code …
- CVE-2021-39185CRITICALCVSS 9.1EG 9.12021-09-01
Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflec…
- CVE-2021-39270HIGHCVSS 7.5EG 7.52021-08-18
In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
- CVE-2021-4024MEDIUMCVSS 6.5EG 6.52021-12-23
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP …
- CVE-2021-41088HIGHCVSS 8.0EG 8.02021-09-23
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The ba…
- CVE-2021-41158MEDIUMCVSS 5.8EG 5.82021-10-26
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, an attacker can perform a SIP d…
- CVE-2021-43531MEDIUMCVSS 4.3EG 4.32021-12-08
When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a sa…
- CVE-2021-44458HIGHCVSS 8.3EG 8.32022-01-10
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would…
- CVE-2021-44935CRITICALCVSS 9.1EG 9.12021-12-14
glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction.
- CVE-2021-45441HIGHCVSS 7.8EG 7.82022-01-10
A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges.…
- CVE-2021-46701HIGHCVSS 7.2EG 7.22022-02-20
PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit events to a socket, potentially interfering with a victim's "now playing" status on Discord.
- CVE-2021-47157CRITICALCVSS 9.8EG 9.82024-03-18
The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.
- CVE-2022-0108MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-0111MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
- CVE-2022-0113MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-0120MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
- CVE-2022-1497MEDIUMCVSS 6.5EG 6.52022-07-26
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
- CVE-2022-1520MEDIUMCVSS 4.3EG 4.32022-12-22
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. After opening and viewing the attached message B, wh…
- CVE-2022-1747MEDIUMCVSS 4.6EG 4.62022-06-24
The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could leverage this vulnerability to print an arbitrary number of …
- CVE-2022-21505MEDIUMCVSS 6.7EG 6.72024-12-24
In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot par…
- CVE-2022-21712HIGHCVSS 7.5EG 7.52022-02-07
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twis…
- CVE-2022-22594MEDIUMCVSS 6.5EG 6.52022-03-18
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user …
- CVE-2022-22637HIGHCVSS 8.8EG 8.82022-09-23
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
- CVE-2022-22757MEDIUMCVSS 6.5EG 6.52022-12-22
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, whi…
- CVE-2022-23032MEDIUMCVSS 5.3EG 5.32022-01-25
In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions whi…
- CVE-2022-23763HIGHCVSS 7.8EG 8.82022-06-28
Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as m…
- CVE-2022-23764CRITICALCVSS 8.8EG 9.82022-08-17
The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote cod…
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →