CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
836 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 6 of 17
- CVE-2026-74934HIGHCVSS 7.5EG 7.52026-08-18
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- CVE-2026-17916HIGHCVSS 7.5EG 7.52026-07-30
Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Lo…
- CVE-2026-16399HIGHCVSS 7.5EG 7.52026-07-21
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16398HIGHCVSS 7.5EG 7.52026-07-21
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-15075HIGHCVSS 7.5EG 7.52026-07-14
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no…
- CVE-2026-15076HIGHCVSS 7.5EG 7.52026-07-14
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating ser…
- CVE-2026-59096HIGHCVSS 7.5EG 7.52026-07-02
Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts…
- CVE-2026-58169HIGHCVSS 7.5EG 7.52026-06-30
Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP peer addresses for loopback clients combined…
- CVE-2026-10846HIGHCVSS 7.5EG 7.52026-06-10
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID,…
- CVE-2026-44894HIGHCVSS 7.5EG 7.52026-06-08
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (ser…
- CVE-2026-47265HIGHCVSS 7.5EG 7.52026-06-02
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookie…
- CVE-2026-40622HIGHCVSS 7.5EG 7.52026-05-20
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost doma…
- CVE-2026-6276HIGHCVSS 7.5EG 7.52026-05-13
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information a…
- CVE-2026-41886HIGHCVSS 7.5EG 7.52026-05-08
locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK registers a window.addEventListener("message", …) handler that dispatches to registered internal handlers (editKey, commi…
- CVE-2026-6903HIGHCVSS 7.5EG 7.52026-04-23
The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated attacker could exploit this vulnerability to read arbitrary files on the host system that…
- CVE-2025-69260HIGHCVSS 7.5EG 7.52026-01-08
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this…
- CVE-2025-69259HIGHCVSS 7.5EG 7.52026-01-08
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exp…
- CVE-2025-69235HIGHCVSS 7.5EG 7.52025-12-30
Whale browser before 4.35.351.12 allows an attacker to bypass the Same-Origin Policy in a sidebar environment.
- CVE-2025-62584HIGHCVSS 7.5EG 7.52025-10-16
Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.
- CVE-2025-53600HIGHCVSS 7.5EG 7.52025-07-04
Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
- CVE-2025-5824HIGHCVSS 7.5EG 7.52025-06-25
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Co…
- CVE-2024-8024HIGHCVSS 7.5EG 7.52025-03-20
A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a …
- CVE-2025-21511HIGHCVSS 7.5EG 7.52025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker wit…
- CVE-2024-50654HIGHCVSS 7.5EG 7.52024-11-15
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.
- CVE-2024-44734HIGHCVSS 7.5EG 7.52024-10-11
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.
- CVE-2024-9393HIGHCVSS 7.5EG 7.52024-10-01
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by…
- CVE-2024-36421HIGHCVSS 7.5EG 7.52024-07-01
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the …
- CVE-2023-49803HIGHCVSS 7.5EG 7.52023-12-11
@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-O…
- CVE-2023-29743HIGHCVSS 7.5EG 7.52023-05-30
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
- CVE-2023-33740HIGHCVSS 7.5EG 7.52023-05-30
Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify parameter in a warning message.
- CVE-2023-30196HIGHCVSS 7.5EG 7.52023-05-30
Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.
- CVE-2023-23578HIGHCVSS 7.5EG 7.52023-05-10
Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.
- CVE-2021-33959HIGHCVSS 7.5EG 7.52023-01-18
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
- CVE-2022-21712HIGHCVSS 7.5EG 7.52022-02-07
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twis…
- CVE-2021-39270HIGHCVSS 7.5EG 7.52021-08-18
In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
- CVE-2020-35556HIGHCVSS 7.5EG 7.52021-02-22
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.
- CVE-2020-4881HIGHCVSS 7.5EG 7.52021-01-19
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this …
- CVE-2020-6881HIGHCVSS 7.5EG 7.52020-12-21
ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception me…
- CVE-2020-9903HIGHCVSS 7.5EG 7.52020-10-16
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
- CVE-2020-14519HIGHCVSS 7.5EG 7.52020-09-16
This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for…
- CVE-2020-11868HIGHCVSS 7.5EG 7.52020-04-17
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet l…
- CVE-2020-8984HIGHCVSS 7.5EG 7.52020-03-24
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
- CVE-2019-19019HIGHCVSS 7.5EG 7.52019-12-02
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell sc…
- CVE-2019-8075HIGHCVSS 7.5EG 7.52019-09-27
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
- CVE-2019-16237HIGHCVSS 7.5EG 7.52019-09-11
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
- CVE-2019-16235HIGHCVSS 7.5EG 7.52019-09-11
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
- CVE-2019-11777HIGHCVSS 7.5EG 7.52019-09-11
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another an…
- CVE-2019-5036HIGHCVSS 7.5EG 7.52019-08-20
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resultin…
- CVE-2019-11723HIGHCVSS 7.5EG 7.52019-07-23
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use t…
- CVE-2018-14903HIGHCVSS 7.5EG 7.52018-08-30
EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious data to the printer.
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →