CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
632 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 7 of 13
- CVE-2024-10534CRITICALCVSS 9.8EG 9.82024-11-15
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection. This issue affects Personnel Attendance Control Systems (PACS) / …
- CVE-2024-10956HIGHCVSS 7.1EG 7.62025-03-20
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and…
- CVE-2024-11045CRITICALCVSS 9.6EG 9.62025-03-20
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of prop…
- CVE-2024-11602HIGHCVSS 7.4EG 7.42025-03-20
A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make …
- CVE-2024-1249HIGHCVSS 7.4EG 7.42024-04-17
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly imp…
- CVE-2024-12973MEDIUMCVSS 4.7EG 4.72025-09-02
Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsing. This issue affects OctoCloud: from s1.09.01 before v1.11.01.
- CVE-2024-13068HIGHCVSS 7.3EG 7.32025-09-03
Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: from s1.02.14 before v1.02.17.
- CVE-2024-14006MEDIUMCVSS 6.1EG 6.12025-10-30
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote atta…
- CVE-2024-21245MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged atta…
- CVE-2024-2182MEDIUMCVSS 6.5EG 6.52024-03-12
A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual mac…
- CVE-2024-22062MEDIUMCVSS 6.3EG 6.32024-07-09
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
- CVE-2024-23458HIGHCVSS 7.3EG 7.32024-08-06
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.
- CVE-2024-2377HIGHCVSS 7.6EG 7.62024-04-30
A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information.
- CVE-2024-23898HIGHCVSS 8.8EG 8.92024-01-24
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulner…
- CVE-2024-2447MEDIUMCVSS 6.5EG 6.52024-04-05
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via…
- CVE-2024-24557MEDIUMCVSS 6.9EG 6.92024-02-01
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being…
- CVE-2024-24782MEDIUMCVSS 4.3EG 4.32024-02-13
An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.
- CVE-2024-25124CRITICALCVSS 9.4EG 9.42024-02-21
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting…
- CVE-2024-25996MEDIUMCVSS 5.3EG 5.32024-03-12
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
- CVE-2024-26135HIGHCVSS 8.3EG 8.32024-02-20
MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perfor…
- CVE-2024-28224MEDIUMCVSS 6.6EG 6.62024-04-08
Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resourc…
- CVE-2024-28883HIGHCVSS 7.4EG 7.42024-05-08
An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End o…
- CVE-2024-31127HIGHCVSS 7.3EG 7.32025-06-04
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
- CVE-2024-32642HIGHCVSS 8.8EG 8.82025-12-03
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8…
- CVE-2024-32764CRITICALCVSS 9.9EG 9.92024-04-26
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fix…
- CVE-2024-36302HIGHCVSS 7.8EG 7.82024-06-10
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2024-36303HIGHCVSS 7.8EG 7.82024-06-10
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privilege…
- CVE-2024-36421HIGHCVSS 7.5EG 7.52024-07-01
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the …
- CVE-2024-36472MEDIUMCVSS 6.5EG 6.52024-05-28
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads un…
- CVE-2024-37661MEDIUMCVSS 6.3EG 6.32024-06-17
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.
- CVE-2024-41143HIGHCVSS 7.8EG 7.82024-07-29
Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the …
- CVE-2024-41475CRITICALCVSS 8.8EG 9.82024-08-12
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
- CVE-2024-41926LOWCVSS 2.7EG 2.72024-08-01
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore cl…
- CVE-2024-44187MEDIUMCVSS 6.5EG 6.52024-09-17
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious webs…
- CVE-2024-44212MEDIUMCVSS 5.3EG 5.32024-12-12
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to…
- CVE-2024-44734HIGHCVSS 7.5EG 7.52024-10-11
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.
- CVE-2024-45352HIGHCVSS 8.8EG 8.82025-03-27
An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
- CVE-2024-45353MEDIUMCVSS 4.3EG 4.32025-03-27
An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is caused by improper input validation and can be exploited by attackers tointent redriction.
- CVE-2024-45354MEDIUMCVSS 4.3EG 4.32025-03-27
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
- CVE-2024-45495MEDIUMCVSS 4.3EG 4.32024-11-29
MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.
- CVE-2024-50654HIGHCVSS 7.5EG 7.52024-11-15
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
- CVE-2024-51037MEDIUMCVSS 5.3EG 5.32024-11-15
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
- CVE-2024-51072MEDIUMCVSS 5.3EG 5.32024-11-22
An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. NOTE: this is disputed by the Supplier because the findings came from a potent…
- CVE-2024-54490MEDIUMCVSS 5.5EG 5.52024-12-12
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.
- CVE-2024-5549HIGHCVSS 8.1EG 8.12024-07-09
A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability also enables attack…
- CVE-2024-55917HIGHCVSS 7.8EG 7.82024-12-31
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
- CVE-2024-55948HIGHCVSS 8.2EG 8.22025-02-04
Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This iss…
- CVE-2024-56170MEDIUMCVSS 5.3EG 5.32024-12-18
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest s…
- CVE-2024-57965UnratedEG 0.02025-01-29
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warnin…
- CVE-2024-5905MEDIUMCVSS 4.4EG 4.42024-06-12
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR age…
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →