CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 6 of 13
- CVE-2023-28795HIGHCVSS 7.8EG 7.82023-10-23
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- CVE-2023-2886HIGHCVSS 4.3EG 7.62023-05-25
Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
- CVE-2023-29505MEDIUMCVSS 4.3EG 4.32023-08-04
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
- CVE-2023-29711CRITICALCVSS 9.8EG 9.82023-06-22
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request.
- CVE-2023-29728CRITICALCVSS 9.8EG 9.82023-05-30
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
- CVE-2023-29743HIGHCVSS 7.5EG 7.52023-05-30
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
- CVE-2023-29745HIGHCVSS 7.1EG 7.12023-05-31
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
- CVE-2023-29751MEDIUMCVSS 5.5EG 5.52023-06-09
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.
- CVE-2023-29753MEDIUMCVSS 5.5EG 5.52023-06-09
An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the SharedPreference files.
- CVE-2023-29756MEDIUMCVSS 5.5EG 5.52023-06-09
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.
- CVE-2023-29867MEDIUMCVSS 6.5EG 6.52023-05-02
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
- CVE-2023-29868MEDIUMCVSS 6.5EG 6.52023-05-02
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
- CVE-2023-30196HIGHCVSS 7.5EG 7.52023-05-30
Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.
- CVE-2023-30856HIGHCVSS 8.3EG 8.32023-04-28
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control webso…
- CVE-2023-30949MEDIUMCVSS 4.3EG 4.32023-07-26
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.
- CVE-2023-30996MEDIUMCVSS 5.3EG 5.32024-02-26
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
- CVE-2023-32223HIGHCVSS 8.8EG 8.82023-06-28
D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.
- CVE-2023-32553MEDIUMCVSS 5.3EG 5.32023-06-26
An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identica…
- CVE-2023-32993MEDIUMCVSS 4.8EG 4.82023-05-16
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to interce…
- CVE-2023-33443CRITICALCVSS 9.8EG 9.82023-06-08
Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.
- CVE-2023-33740HIGHCVSS 7.5EG 7.52023-05-30
Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify parameter in a warning message.
- CVE-2023-3581MEDIUMCVSS 6.2EG 6.22023-07-17
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
- CVE-2023-3654CRITICALCVSS 9.4EG 9.42023-10-03
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP en…
- CVE-2023-37210MEDIUMCVSS 6.5EG 6.52023-07-05
A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
- CVE-2023-4045MEDIUMCVSS 5.3EG 5.32023-08-01
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefo…
- CVE-2023-40547HIGHCVSS 8.3EG 8.32024-01-25
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completel…
- CVE-2023-44189MEDIUMCVSS 5.4EG 6.12023-10-11
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjac…
- CVE-2023-44190MEDIUMCVSS 5.4EG 6.12023-10-11
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addres…
- CVE-2023-46715MEDIUMCVSS 5.0EG 5.02025-01-14
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets s…
- CVE-2023-47193HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47194HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47195HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47196HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47197HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47198HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47199HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47200HIGHCVSS 7.8EG 7.82024-01-23
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execut…
- CVE-2023-49803HIGHCVSS 7.5EG 7.52023-12-11
@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-O…
- CVE-2023-49805HIGHCVSS 8.8EG 8.82023-12-11
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to acces…
- CVE-2023-49899CRITICALCVSS 9.8EG 9.82026-07-16
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
- CVE-2023-5718MEDIUMCVSS 4.3EG 4.32023-10-23
The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame targeting a sensitive resource (i.e. a locally accessible fi…
- CVE-2023-5851MEDIUMCVSS 4.3EG 4.32023-11-01
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-5853MEDIUMCVSS 4.3EG 4.32023-11-01
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-5858MEDIUMCVSS 4.3EG 4.32023-11-01
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
- CVE-2023-5859MEDIUMCVSS 4.3EG 4.32023-11-01
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
- CVE-2023-5973MEDIUMCVSS 4.3EG 4.32024-04-05
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade …
- CVE-2024-0009MEDIUMCVSS 6.3EG 6.32024-02-14
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
- CVE-2024-0749MEDIUMCVSS 4.3EG 4.32024-01-23
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
- CVE-2024-0814MEDIUMCVSS 6.5EG 6.52024-01-24
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-10460MEDIUMCVSS 5.3EG 5.32024-10-29
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →