CWE-346 · 692 records
Origin Validation Error
CVEs in this class
693 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2025-34291Weaponized | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCElangflow · langflow · CWE-346 | Critical9.4 | KEV | 92.8% | Dec 5, 2025 |
86Now | CVE-2015-4495Weaponized | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | High8.8 | KEV | 68.6% | Aug 7, 2015 |
60This week | CVE-2023-29711No exploit | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via craftedinterlink · psg-5124 firmware · CWE-346 | Critical9.8 | — | 70.3% | Jun 22, 2023 |
55Plan | CVE-2020-16952Weaponized | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-346 | High8.6 | — | 71.1% | Oct 16, 2020 |
55Plan | CVE-2024-23898Proof of concept | Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests majenkins · jenkins · CWE-346 | High8.8 | — | 67.2% | Jan 24, 2024 |
52Plan | CVE-2009-1185Weaponized | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senudev project · udev · CWE-346 | High7.2 | — | 80.4% | Apr 17, 2009 |
41Plan | CVE-2000-1218No exploit | The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to microsoft · windows 2000 · CWE-346 | Critical9.8 | — | 6.3% | Apr 14, 2000 |
41Plan | CVE-2019-3980Proof of concept | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executablsolarwinds · dameware mini remote control · CWE-346 | Critical9.8 | — | 5.1% | Oct 8, 2019 |
40Plan | CVE-2019-8069No exploit | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.adobe · flash player desktop runtime · CWE-346 | Critical9.8 | — | 4.3% | Sep 12, 2019 |
40Plan | CVE-2018-15723No exploit | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.logitech · harmony hub firmware · CWE-346 | Critical9.8 | — | 3.7% | Dec 20, 2018 |
40Plan | CVE-2023-33443No exploit | Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrbesder · videoplaytool · CWE-346 | Critical9.8 | — | 3.5% | Jun 8, 2023 |
40Plan | CVE-2026-42901No exploit | Microsoft Entra ID Elevation of Privilege Vulnerabilitymicrosoft · entra id · CWE-346 | Critical10.0 | — | 0.5% | May 22, 2026 |
40Plan | CVE-2023-30856No exploit | eDEX-UI cross-site websocket hijacking vulnerability enables remote command executionedex-ui project · edex-ui · CWE-346 | Critical10.0 | — | 0.3% | Apr 28, 2023 |
39Monitor | CVE-2021-26291Proof of concept | block repositories using http by defaultapache · maven · CWE-346 | Critical9.1 | — | 8.7% | Apr 23, 2021 |
39Monitor | CVE-2022-41924Proof of concept | Tailscale Windows daemon is vulnerable to RCE via CSRFtailscale · tailscale · CWE-346 | Critical9.6 | — | 1.8% | Nov 23, 2022 |
39Monitor | CVE-2019-16517No exploit | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-346 | Critical9.8 | — | 1.3% | Jan 23, 2020 |
39Monitor | CVE-2018-5116No exploit | WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.mozilla · firefox · CWE-346 | Critical9.8 | — | 1.2% | Jun 11, 2018 |
39Monitor | CVE-2003-0174No exploit | The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP ssgi · irix · CWE-346 | Critical9.8 | — | 1.0% | May 12, 2003 |
39Monitor | CVE-2020-26527Proof of concept | An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.damstratechnology · smart asset · CWE-346 | Critical9.8 | — | 0.9% | Oct 2, 2020 |
39Monitor | CVE-2019-15020No exploit | A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softwzingbox · inspector · CWE-346 | Critical9.8 | — | 0.9% | Oct 9, 2019 |
39Monitor | CVE-2017-20146No exploit | Improper access control in github.com/gorilla/handlersgorillatoolkit · handlers · CWE-346 | Critical9.8 | — | 0.7% | Dec 27, 2022 |
39Monitor | CVE-2024-25124No exploit | Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentialsgofiber · fiber · CWE-346 | Critical9.8 | — | 0.7% | Feb 21, 2024 |
39Monitor | CVE-2022-23764No exploit | TERUTEN WebCube update remote code execution vulnerabilityteruten · webcube · CWE-346 | Critical9.8 | — | 0.7% | Aug 17, 2022 |
39Monitor | CVE-2023-29728No exploit | The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privapplika · call blocker · CWE-346 | Critical9.8 | — | 0.6% | May 30, 2023 |
39Monitor | CVE-2024-9392No exploit | A compromised content process could have allowed for the arbitrary loading of cross-origin pages.mozilla · firefox · CWE-346 | Critical9.8 | — | 0.5% | Oct 1, 2024 |
- CVE-2025-3429195Now
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
CriticalCVSS 9.4KEVWeaponizedEPSS 93%langflow · langflowDec 5, 2025
- CVE-2015-449586Now
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
HighCVSS 8.8KEVWeaponizedEPSS 69%mozilla · firefoxAug 7, 2015
- CVE-2023-2971160This week
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted
CriticalCVSS 9.8No exploitEPSS 70%interlink · psg-5124 firmwareJun 22, 2023
- CVE-2020-1695255Plan
Microsoft SharePoint Remote Code Execution Vulnerability
HighCVSS 8.6WeaponizedEPSS 71%microsoft · sharepoint enterprise serverOct 16, 2020
- CVE-2024-2389855Plan
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests ma
HighCVSS 8.8Proof of conceptEPSS 67%jenkins · jenkinsJan 24, 2024
- CVE-2009-118552Plan
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen
HighCVSS 7.2WeaponizedEPSS 80%udev project · udevApr 17, 2009
- CVE-2000-121841Plan
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to
CriticalCVSS 9.8No exploitEPSS 6%microsoft · windows 2000Apr 14, 2000
- CVE-2019-398041Plan
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executabl
CriticalCVSS 9.8Proof of conceptEPSS 5%solarwinds · dameware mini remote controlOct 8, 2019
- CVE-2019-806940Plan
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%adobe · flash player desktop runtimeSep 12, 2019
- CVE-2018-1572340Plan
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
CriticalCVSS 9.8No exploitEPSS 4%logitech · harmony hub firmwareDec 20, 2018
- CVE-2023-3344340Plan
Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitr
CriticalCVSS 9.8No exploitEPSS 4%besder · videoplaytoolJun 8, 2023
- CVE-2026-4290140Plan
Microsoft Entra ID Elevation of Privilege Vulnerability
CriticalCVSS 10.0No exploitEPSS 0%microsoft · entra idMay 22, 2026
- CVE-2023-3085640Plan
eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
CriticalCVSS 10.0No exploitEPSS 0%edex-ui project · edex-uiApr 28, 2023
- CVE-2021-2629139Monitor
block repositories using http by default
CriticalCVSS 9.1Proof of conceptEPSS 9%apache · mavenApr 23, 2021
- CVE-2022-4192439Monitor
Tailscale Windows daemon is vulnerable to RCE via CSRF
CriticalCVSS 9.6Proof of conceptEPSS 2%tailscale · tailscaleNov 23, 2022
- CVE-2019-1651739Monitor
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
CriticalCVSS 9.8No exploitEPSS 1%connectwise · controlJan 23, 2020
- CVE-2018-511639Monitor
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.
CriticalCVSS 9.8No exploitEPSS 1%mozilla · firefoxJun 11, 2018
- CVE-2003-017439Monitor
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP s
CriticalCVSS 9.8No exploitEPSS 1%sgi · irixMay 12, 2003
- CVE-2020-2652739Monitor
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.
CriticalCVSS 9.8Proof of conceptEPSS 1%damstratechnology · smart assetOct 2, 2020
- CVE-2019-1502039Monitor
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw
CriticalCVSS 9.8No exploitEPSS 1%zingbox · inspectorOct 9, 2019
- CVE-2017-2014639Monitor
Improper access control in github.com/gorilla/handlers
CriticalCVSS 9.8No exploitEPSS 1%gorillatoolkit · handlersDec 27, 2022
- CVE-2024-2512439Monitor
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
CriticalCVSS 9.8No exploitEPSS 1%gofiber · fiberFeb 21, 2024
- CVE-2022-2376439Monitor
TERUTEN WebCube update remote code execution vulnerability
CriticalCVSS 9.8No exploitEPSS 1%teruten · webcubeAug 17, 2022
- CVE-2023-2972839Monitor
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of priv
CriticalCVSS 9.8No exploitEPSS 1%applika · call blockerMay 30, 2023
- CVE-2024-939239Monitor
A compromised content process could have allowed for the arbitrary loading of cross-origin pages.
CriticalCVSS 9.8No exploitEPSS 1%mozilla · firefoxOct 1, 2024