CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 5 of 13
- CVE-2022-24762MEDIUMCVSS 6.5EG 6.52022-03-14
sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurri…
- CVE-2022-25146MEDIUMCVSS 5.3EG 5.32022-03-03
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exf…
- CVE-2022-25227HIGHCVSS 8.8EG 8.82022-05-20
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocke…
- CVE-2022-26137HIGHCVSS 8.8EG 8.82022-07-20
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only kno…
- CVE-2022-29818HIGHCVSS 3.9EG 7.12022-04-28
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
- CVE-2022-29915MEDIUMCVSS 4.3EG 4.32022-12-22
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.
- CVE-2022-30228HIGHCVSS 8.8EG 8.82022-06-14
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimat…
- CVE-2022-31024MEDIUMCVSS 6.5EG 6.52022-06-02
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. …
- CVE-2022-31151LOWCVSS 3.7EG 3.72022-07-21
Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may l…
- CVE-2022-32144HIGHCVSS 8.6EG 8.62024-12-20
There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability has been assigned a Common …
- CVE-2022-3457CRITICALCVSS 9.8EG 9.82022-10-13
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
- CVE-2022-38472MEDIUMCVSS 6.5EG 6.52022-12-22
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed…
- CVE-2022-40140MEDIUMCVSS 5.5EG 5.52022-09-19
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execu…
- CVE-2022-41294MEDIUMCVSS 6.5EG 6.52022-10-06
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.
- CVE-2022-41749HIGHCVSS 7.8EG 7.82022-10-10
An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on…
- CVE-2022-41924CRITICALCVSS 9.6EG 9.62022-11-23
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bou…
- CVE-2022-41961MEDIUMCVSS 4.3EG 4.32022-12-16
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they cou…
- CVE-2022-42860MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1, macOS Ventura 13. An app may be able to modify protected parts of the file system
- CVE-2022-42927HIGHCVSS 8.1EG 8.12022-12-22
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102…
- CVE-2022-45139MEDIUMCVSS 5.3EG 5.32023-02-27
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information lik…
- CVE-2022-46718MEDIUMCVSS 5.5EG 5.52023-06-23
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to read sensitive location information
- CVE-2022-4917MEDIUMCVSS 4.3EG 4.32023-07-29
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)
- CVE-2022-50925CRITICALCVSS 9.8EG 9.82026-01-13
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, openin…
- CVE-2022-50975HIGHCVSS 8.8EG 8.82026-02-02
An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.
- CVE-2023-0132MEDIUMCVSS 6.5EG 6.52023-01-10
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-0957CRITICALCVSS 8.2EG 9.62023-03-03
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s c…
- CVE-2023-20275MEDIUMCVSS 4.1EG 4.12023-12-12
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's s…
- CVE-2023-21260MEDIUMCVSS 5.5EG 5.52023-07-13
In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user con…
- CVE-2023-22899MEDIUMCVSS 5.9EG 5.92023-01-10
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
- CVE-2023-23561MEDIUMCVSS 5.5EG 5.52023-05-30
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.
- CVE-2023-23578HIGHCVSS 7.5EG 7.52023-05-10
Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.
- CVE-2023-23601MEDIUMCVSS 6.5EG 6.52023-06-02
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
- CVE-2023-2445MEDIUMCVSS 4.9EG 4.92023-05-02
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.
- CVE-2023-25188MEDIUMCVSS 5.1EG 5.12023-06-16
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (whi…
- CVE-2023-25366CRITICALCVSS 9.8EG 9.82023-06-16
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
- CVE-2023-2589MEDIUMCVSS 5.9EG 5.92023-06-07
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a p…
- CVE-2023-26114HIGHCVSS 8.2EG 8.22023-03-23
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-…
- CVE-2023-2639MEDIUMCVSS 4.1EG 4.12023-06-13
The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a…
- CVE-2023-27360HIGHCVSS 8.8EG 8.82024-05-03
NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to explo…
- CVE-2023-27745HIGHCVSS 8.8EG 8.82023-06-02
An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.
- CVE-2023-27932MEDIUMCVSS 5.5EG 5.52023-05-08
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
- CVE-2023-27944HIGHCVSS 8.6EG 8.62023-05-08
This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to break out of its sandbox.
- CVE-2023-27962MEDIUMCVSS 5.5EG 5.52023-05-08
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to modify protected parts of the file system.
- CVE-2023-28164MEDIUMCVSS 6.5EG 6.52023-06-02
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
- CVE-2023-28191MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypa…
- CVE-2023-28318MEDIUMCVSS 5.3EG 5.32023-05-09
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, h…
- CVE-2023-28349HIGHCVSS 8.8EG 8.82023-05-31
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves a…
- CVE-2023-2848HIGHCVSS 8.0EG 8.02023-09-14
Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.
- CVE-2023-2850MEDIUMCVSS 4.7EG 4.72023-07-25
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
- CVE-2023-28794MEDIUMCVSS 4.3EG 4.32023-11-06
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →