CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
836 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 10 of 17
- CVE-2025-42706MEDIUMCVSS 6.5EG 6.52025-10-08
A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Window…
- CVE-2025-56648MEDIUMCVSS 6.5EG 6.52025-09-17
npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response to steal source code when developers visit them.
- CVE-2025-8881MEDIUMCVSS 6.5EG 6.52025-08-13
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security sev…
- CVE-2025-30360MEDIUMCVSS 6.5EG 6.52025-06-03
webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based…
- CVE-2025-25302MEDIUMCVSS 6.5EG 6.52025-03-03
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API.…
- CVE-2025-24010MEDIUMCVSS 6.5EG 6.52025-01-20
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket conn…
- CVE-2025-23109MEDIUMCVSS 6.5EG 6.52025-01-11
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.
- CVE-2024-44187MEDIUMCVSS 6.5EG 6.52024-09-17
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious webs…
- CVE-2024-36472MEDIUMCVSS 6.5EG 6.52024-05-28
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads un…
- CVE-2024-2447MEDIUMCVSS 6.5EG 6.52024-04-05
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via…
- CVE-2024-2182MEDIUMCVSS 6.5EG 6.52024-03-12
A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual mac…
- CVE-2024-0814MEDIUMCVSS 6.5EG 6.52024-01-24
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-37210MEDIUMCVSS 6.5EG 6.52023-07-05
A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
- CVE-2023-28164MEDIUMCVSS 6.5EG 6.52023-06-02
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
- CVE-2023-23601MEDIUMCVSS 6.5EG 6.52023-06-02
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
- CVE-2023-29868MEDIUMCVSS 6.5EG 6.52023-05-02
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
- CVE-2023-29867MEDIUMCVSS 6.5EG 6.52023-05-02
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
- CVE-2023-0132MEDIUMCVSS 6.5EG 6.52023-01-10
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-38472MEDIUMCVSS 6.5EG 6.52022-12-22
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed…
- CVE-2022-22757MEDIUMCVSS 6.5EG 6.52022-12-22
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, whi…
- CVE-2022-41294MEDIUMCVSS 6.5EG 6.52022-10-06
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807.
- CVE-2022-1497MEDIUMCVSS 6.5EG 6.52022-07-26
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
- CVE-2022-31024MEDIUMCVSS 6.5EG 6.52022-06-02
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. …
- CVE-2022-22594MEDIUMCVSS 6.5EG 6.52022-03-18
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user …
- CVE-2022-24762MEDIUMCVSS 6.5EG 6.52022-03-14
sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurri…
- CVE-2022-0120MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
- CVE-2022-0113MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2022-0111MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
- CVE-2022-0108MEDIUMCVSS 6.5EG 6.52022-02-12
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2020-9060MEDIUMCVSS 6.5EG 6.52022-01-10
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 vers…
- CVE-2021-4024MEDIUMCVSS 6.5EG 6.52021-12-23
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP …
- CVE-2021-38507MEDIUMCVSS 6.5EG 6.52021-12-08
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port …
- CVE-2021-38497MEDIUMCVSS 6.5EG 6.52021-11-03
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < …
- CVE-2021-21229MEDIUMCVSS 6.5EG 6.52021-04-30
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- CVE-2021-21211MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21209MEDIUMCVSS 6.5EG 6.52021-04-26
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-28048MEDIUMCVSS 6.5EG 6.52021-04-14
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-23986MEDIUMCVSS 6.5EG 6.52021-03-31
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origi…
- CVE-2021-21175MEDIUMCVSS 6.5EG 6.52021-03-09
Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21164MEDIUMCVSS 6.5EG 6.52021-03-09
Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21163MEDIUMCVSS 6.5EG 6.52021-03-09
Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.
- CVE-2021-21136MEDIUMCVSS 6.5EG 6.52021-02-09
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2021-21135MEDIUMCVSS 6.5EG 6.52021-02-09
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2020-15733MEDIUMCVSS 6.5EG 6.52020-12-14
An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.
- CVE-2019-8754MEDIUMCVSS 6.5EG 6.52020-10-27
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. A malicious HTML doc…
- CVE-2020-15682MEDIUMCVSS 6.5EG 6.52020-10-22
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in …
- CVE-2020-15773MEDIUMCVSS 6.5EG 6.52020-09-18
An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previous…
- CVE-2020-15652MEDIUMCVSS 6.5EG 6.52020-08-10
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox E…
- CVE-2020-16168MEDIUMCVSS 6.5EG 6.52020-08-07
Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests via unspecified vectors.
- CVE-2019-5062MEDIUMCVSS 6.5EG 6.52019-12-12
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentica…
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →