CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
836 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 1 of 17
- CVE-2025-34291CRITICALCVSS 8.8EG 9.0⚠ KEV2025-12-05
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a re…
- CVE-2015-4495CRITICALCVSS 8.8EG 9.0⚠ KEV2015-08-08
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted…
- CVE-2026-59971CRITICALCVSS 10.0EG 10.02026-09-11
MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_sett…
- CVE-2026-47691CRITICALCVSS 10.0EG 10.02026-06-08
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cach…
- CVE-2026-45674CRITICALCVSS 10.0EG 10.02026-06-08
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS response…
- CVE-2026-42901CRITICALCVSS 10.0EG 10.02026-05-22
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-9265CRITICALCVSS 10.0EG 10.02025-10-13
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affec…
- CVE-2021-37705CRITICALCVSS 10.0EG 10.02021-08-13
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API call…
- CVE-2024-32764CRITICALCVSS 9.9EG 9.92024-04-26
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fix…
- CVE-2026-104056CRITICALCVSS 9.8EG 9.82026-10-01
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled…
- CVE-2026-84140CRITICALCVSS 9.8EG 9.82026-09-01
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- CVE-2026-84133CRITICALCVSS 9.8EG 9.82026-09-01
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- CVE-2026-84129CRITICALCVSS 9.8EG 9.82026-09-01
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- CVE-2026-18847CRITICALCVSS 9.8EG 9.82026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
- CVE-2026-16442CRITICALCVSS 9.8EG 9.82026-08-05
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted t…
- CVE-2026-16387CRITICALCVSS 9.8EG 9.82026-07-21
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16358CRITICALCVSS 9.8EG 9.82026-07-21
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16375CRITICALCVSS 9.8EG 9.82026-07-21
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2026-16349CRITICALCVSS 9.8EG 9.82026-07-21
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
- CVE-2023-49899CRITICALCVSS 9.8EG 9.82026-07-16
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
- CVE-2026-44649CRITICALCVSS 9.8EG 9.82026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authel…
- CVE-2026-6508CRITICALCVSS 9.8EG 9.82026-05-07
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liderahenk: from 2.0.1 before 2.0.2.
- CVE-2026-2790CRITICALCVSS 9.8EG 9.82026-02-24
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
- CVE-2022-50925CRITICALCVSS 9.8EG 9.82026-01-13
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, openin…
- CVE-2025-69258CRITICALCVSS 9.8EG 9.82026-01-08
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM o…
- CVE-2025-30466CRITICALCVSS 9.8EG 9.82025-05-29
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
- CVE-2024-8487CRITICALCVSS 9.8EG 9.82025-03-20
A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to…
- CVE-2024-10534CRITICALCVSS 9.8EG 9.82024-11-15
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection. This issue affects Personnel Attendance Control Systems (PACS) / …
- CVE-2024-9392CRITICALCVSS 9.8EG 9.82024-10-01
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
- CVE-2021-47157CRITICALCVSS 9.8EG 9.82024-03-18
The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.
- CVE-2023-29711CRITICALCVSS 9.8EG 9.82023-06-22
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request.
- CVE-2023-25366CRITICALCVSS 9.8EG 9.82023-06-16
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
- CVE-2023-33443CRITICALCVSS 9.8EG 9.82023-06-08
Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.
- CVE-2023-29728CRITICALCVSS 9.8EG 9.82023-05-30
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
- CVE-2017-20146CRITICALCVSS 9.8EG 9.82022-12-27
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
- CVE-2022-3457CRITICALCVSS 9.8EG 9.82022-10-13
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
- CVE-2020-26527CRITICALCVSS 9.8EG 9.82020-10-02
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control…
- CVE-2019-4640CRITICALCVSS 9.8EG 9.82020-02-19
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.
- CVE-2019-16517CRITICALCVSS 9.8EG 9.82020-01-23
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to …
- CVE-2019-15020CRITICALCVSS 9.8EG 9.82019-10-09
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.
- CVE-2019-3980CRITICALCVSS 9.8EG 9.82019-10-08
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card …
- CVE-2019-8069CRITICALCVSS 9.8EG 9.82019-09-12
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.
- CVE-2018-5409CRITICALCVSS 9.8EG 9.82019-05-08
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising t…
- CVE-2018-15723CRITICALCVSS 9.8EG 9.82018-12-20
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g…
- CVE-2018-5116CRITICALCVSS 9.8EG 9.82018-06-11
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact …
- CVE-2017-13274CRITICALCVSS 9.8EG 9.82018-04-04
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2003-0174CRITICALCVSS 9.8EG 9.82003-05-12
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
- CVE-2000-1218CRITICALCVSS 9.8EG 9.82000-04-14
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote…
- CVE-2024-41475CRITICALCVSS 8.8EG 9.82024-08-12
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
- CVE-2022-23764CRITICALCVSS 8.8EG 9.82022-08-17
The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote cod…
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →