CWE-346— Origin Validation Error
468 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 7 of 10
- CVE-2024-36302HIGHCVSS 7.8EG 7.82024-06-10
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2024-36303HIGHCVSS 7.8EG 7.82024-06-10
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2024-36421HIGHCVSS 7.5EG 7.52024-07-01
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the …
- CVE-2024-36472MEDIUMCVSS 6.5EG 6.52024-05-28
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads un…
- CVE-2024-37661MEDIUMCVSS 6.3EG 6.32024-06-17
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.
- CVE-2024-41143HIGHCVSS 7.8EG 7.82024-07-29
Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the …
- CVE-2024-41475HIGHCVSS 8.8EG 9.82024-08-12
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
- CVE-2024-41926LOWCVSS 2.7EG 2.72024-08-01
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore cl…
- CVE-2024-44187MEDIUMCVSS 6.5EG 6.52024-09-17
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious webs…
- CVE-2024-44212MEDIUMCVSS 5.3EG 5.32024-12-12
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to…
- CVE-2024-44734HIGHCVSS 7.5EG 7.52024-10-11
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.
- CVE-2024-45352HIGHCVSS 8.8EG 8.82025-03-27
An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
- CVE-2024-45353MEDIUMCVSS 4.3EG 4.32025-03-27
An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction.
- CVE-2024-45354MEDIUMCVSS 4.3EG 4.32025-03-27
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
- CVE-2024-45495MEDIUMCVSS 4.3EG 4.32024-11-29
MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.
- CVE-2024-50654HIGHCVSS 7.5EG 7.52024-11-15
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
- CVE-2024-51037MEDIUMCVSS 5.3EG 5.32024-11-15
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
- CVE-2024-51072MEDIUMCVSS 5.3EG 5.32024-11-22
An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. NOTE: this is disputed by the Supplier because the findings came from a potent…
- CVE-2024-54490MEDIUMCVSS 5.5EG 5.52024-12-12
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.
- CVE-2024-5549HIGHCVSS 8.1EG 8.12024-07-09
A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability also enables attack…
- CVE-2024-55917HIGHCVSS 7.8EG 7.82024-12-31
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
- CVE-2024-55948HIGHCVSS 8.2EG 8.22025-02-04
Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This iss…
- CVE-2024-56170MEDIUMCVSS 5.3EG 5.32024-12-18
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest s…
- CVE-2024-57965NONECVSS 0.0EG 0.02025-01-29
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warnin…
- CVE-2024-5905MEDIUMCVSS 4.4EG 4.42024-06-12
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR age…
- CVE-2024-6301MEDIUMCVSS 5.3EG 5.32024-06-25
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs
- CVE-2024-6674HIGHCVSS 7.1EG 8.12024-10-29
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also …
- CVE-2024-6844MEDIUMCVSS 5.3EG 5.32025-03-20
A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is passed through the unquote_plus function, which converts the '+' chara…
- CVE-2024-7819HIGHCVSS 7.4EG 7.42025-03-20
A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malic…
- CVE-2024-7978MEDIUMCVSS 4.3EG 4.32024-08-21
Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security…
- CVE-2024-8024HIGHCVSS 7.5EG 7.52025-03-20
A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a …
- CVE-2024-8183HIGHCVSS 7.6EG 7.62025-03-20
A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential da…
- CVE-2024-8487CRITICALCVSS 9.8EG 7.42025-03-20
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to…
- CVE-2024-9392CRITICALCVSS 9.8EG 9.82024-10-01
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
- CVE-2024-9393HIGHCVSS 7.5EG 7.52024-10-01
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by…
- CVE-2025-10193HIGHCVSS 7.4EG 0.02025-09-11
DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user…
- CVE-2025-10201HIGHCVSS 8.8EG 8.82025-09-10
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-1083LOWCVSS 3.1EG 3.12025-02-06
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation leads to permissive cro…
- CVE-2025-1102MEDIUMCVSS 5.5EG 5.52025-02-12
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URL…
- CVE-2025-11304MEDIUMCVSS 6.3EG 6.32025-10-05
A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown functionality of the component API. Executing manipulation can lead to permissive cross-domain policy with untrusted domains. T…
- CVE-2025-12245MEDIUMCVSS 5.3EG 5.32025-10-27
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl l…
- CVE-2025-12905MEDIUMCVSS 5.4EG 5.42025-11-08
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)
- CVE-2025-13593MEDIUMCVSS 6.1EG 6.12026-05-27
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
- CVE-2025-13947HIGHCVSS 7.4EG 7.42025-12-03
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that …
- CVE-2025-14279HIGHCVSS 8.1EG 8.12026-01-12
MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections an…
- CVE-2025-14331MEDIUMCVSS 6.5EG 6.52025-12-09
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
- CVE-2025-20364MEDIUMCVSS 4.3EG 4.32025-09-24
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vuln…
- CVE-2025-2140MEDIUMCVSS 5.7EG 5.72025-10-12
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
- CVE-2025-21497MEDIUMCVSS 5.5EG 5.52025-01-21
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attack…
- CVE-2025-21511HIGHCVSS 7.5EG 7.52025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker wit…
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →