CWE-346— Origin Validation Error
468 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 6 of 10
- CVE-2023-4045MEDIUMCVSS 5.3EG 5.32023-08-01
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefo…
- CVE-2023-40547HIGHCVSS 8.3EG 8.32024-01-25
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completel…
- CVE-2023-44189MEDIUMCVSS 6.1EG 6.12023-10-11
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjac…
- CVE-2023-44190MEDIUMCVSS 6.1EG 6.12023-10-11
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addres…
- CVE-2023-46715MEDIUMCVSS 5.0EG 5.02025-01-14
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets s…
- CVE-2023-47193HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47194HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47195HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47196HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47197HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47198HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47199HIGHCVSS 7.8EG 7.82024-01-23
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2023-47200HIGHCVSS 7.8EG 7.82024-01-23
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execut…
- CVE-2023-49803HIGHCVSS 8.6EG 8.62023-12-11
@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-O…
- CVE-2023-49805MEDIUMCVSS 6.0EG 6.02023-12-11
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to acces…
- CVE-2023-5718MEDIUMCVSS 4.3EG 4.32023-10-23
The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame targeting a sensitive resource (i.e. a locally accessible fi…
- CVE-2023-5851MEDIUMCVSS 4.3EG 4.32023-11-01
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-5853MEDIUMCVSS 4.3EG 4.32023-11-01
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-5858MEDIUMCVSS 4.3EG 4.32023-11-01
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
- CVE-2023-5859MEDIUMCVSS 4.3EG 4.32023-11-01
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
- CVE-2023-5973MEDIUMCVSS 4.3EG 4.32024-04-05
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade …
- CVE-2024-0009MEDIUMCVSS 6.3EG 6.32024-02-14
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
- CVE-2024-0749MEDIUMCVSS 4.3EG 4.32024-01-23
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
- CVE-2024-0814MEDIUMCVSS 6.5EG 6.52024-01-24
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-10460MEDIUMCVSS 5.3EG 5.32024-10-29
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
- CVE-2024-10534CRITICALCVSS 9.8EG 9.82024-11-15
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection. This issue affects Personnel Attendance Control Systems (PACS) / …
- CVE-2024-10956HIGHCVSS 7.1EG 7.62025-03-20
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and…
- CVE-2024-11045CRITICALCVSS 9.6EG 9.62025-03-20
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of prop…
- CVE-2024-11602HIGHCVSS 7.4EG 7.42025-03-20
A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make …
- CVE-2024-1249HIGHCVSS 7.4EG 7.42024-04-17
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly imp…
- CVE-2024-12973MEDIUMCVSS 4.7EG 4.72025-09-02
Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsing. This issue affects OctoCloud: from s1.09.01 before v1.11.01.
- CVE-2024-13068HIGHCVSS 7.3EG 7.32025-09-03
Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: from s1.02.14 before v1.02.17.
- CVE-2024-14006MEDIUMCVSS 6.1EG 6.12025-10-30
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote atta…
- CVE-2024-21245MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged atta…
- CVE-2024-2182MEDIUMCVSS 6.5EG 6.52024-03-12
A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual mac…
- CVE-2024-22062MEDIUMCVSS 6.3EG 6.32024-07-09
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
- CVE-2024-23458HIGHCVSS 7.3EG 7.32024-08-06
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.
- CVE-2024-2377HIGHCVSS 7.6EG 7.62024-04-30
A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information.
- CVE-2024-23898HIGHCVSS 8.8EG 8.82024-01-24
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulner…
- CVE-2024-2447MEDIUMCVSS 6.5EG 6.52024-04-05
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via…
- CVE-2024-24557MEDIUMCVSS 6.9EG 6.92024-02-01
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being…
- CVE-2024-24782MEDIUMCVSS 4.3EG 4.32024-02-13
An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.
- CVE-2024-25124CRITICALCVSS 9.4EG 9.42024-02-21
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting…
- CVE-2024-25996MEDIUMCVSS 5.3EG 5.32024-03-12
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
- CVE-2024-26135HIGHCVSS 8.3EG 8.32024-02-20
MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perfor…
- CVE-2024-28224MEDIUMCVSS 6.6EG 6.62024-04-08
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resourc…
- CVE-2024-28883HIGHCVSS 7.4EG 7.42024-05-08
An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End o…
- CVE-2024-31127HIGHCVSS 7.3EG 7.32025-06-04
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
- CVE-2024-32642HIGHCVSS 8.8EG 8.82025-12-03
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8…
- CVE-2024-32764CRITICALCVSS 9.9EG 9.92024-04-26
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fix…
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →