Skip to content
Noroxi

CWE-346 · 692 records

Origin Validation Error

CVEs in this class

693 records

  • Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

    CriticalCVSS 9.4KEVWeaponizedEPSS 93%

    langflow · langflowDec 5, 2025

  • The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxAug 7, 2015

  • CVE-2023-29711
    60This week

    An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted

    CriticalCVSS 9.8No exploitEPSS 70%

    interlink · psg-5124 firmwareJun 22, 2023

  • Microsoft SharePoint Remote Code Execution Vulnerability

    HighCVSS 8.6WeaponizedEPSS 71%

    microsoft · sharepoint enterprise serverOct 16, 2020

  • Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests ma

    HighCVSS 8.8Proof of conceptEPSS 67%

    jenkins · jenkinsJan 24, 2024

  • udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen

    HighCVSS 7.2WeaponizedEPSS 80%

    udev project · udevApr 17, 2009

  • The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to

    CriticalCVSS 9.8No exploitEPSS 6%

    microsoft · windows 2000Apr 14, 2000

  • The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executabl

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    solarwinds · dameware mini remote controlOct 8, 2019

  • Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.

    CriticalCVSS 9.8No exploitEPSS 4%

    adobe · flash player desktop runtimeSep 12, 2019

  • The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.

    CriticalCVSS 9.8No exploitEPSS 4%

    logitech · harmony hub firmwareDec 20, 2018

  • Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitr

    CriticalCVSS 9.8No exploitEPSS 4%

    besder · videoplaytoolJun 8, 2023

  • Microsoft Entra ID Elevation of Privilege Vulnerability

    CriticalCVSS 10.0No exploitEPSS 0%

    microsoft · entra idMay 22, 2026

  • eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution

    CriticalCVSS 10.0No exploitEPSS 0%

    edex-ui project · edex-uiApr 28, 2023

  • block repositories using http by default

    CriticalCVSS 9.1Proof of conceptEPSS 9%

    apache · mavenApr 23, 2021

  • Tailscale Windows daemon is vulnerable to RCE via CSRF

    CriticalCVSS 9.6Proof of conceptEPSS 2%

    tailscale · tailscaleNov 23, 2022

  • An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    CriticalCVSS 9.8No exploitEPSS 1%

    connectwise · controlJan 23, 2020

  • CVE-2018-5116
    39Monitor

    WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.

    CriticalCVSS 9.8No exploitEPSS 1%

    mozilla · firefoxJun 11, 2018

  • CVE-2003-0174
    39Monitor

    The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP s

    CriticalCVSS 9.8No exploitEPSS 1%

    sgi · irixMay 12, 2003

  • An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    damstratechnology · smart assetOct 2, 2020

  • A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw

    CriticalCVSS 9.8No exploitEPSS 1%

    zingbox · inspectorOct 9, 2019

  • Improper access control in github.com/gorilla/handlers

    CriticalCVSS 9.8No exploitEPSS 1%

    gorillatoolkit · handlersDec 27, 2022

  • Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials

    CriticalCVSS 9.8No exploitEPSS 1%

    gofiber · fiberFeb 21, 2024

  • TERUTEN WebCube update remote code execution vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    teruten · webcubeAug 17, 2022

  • The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of priv

    CriticalCVSS 9.8No exploitEPSS 1%

    applika · call blockerMay 30, 2023

  • CVE-2024-9392
    39Monitor

    A compromised content process could have allowed for the arbitrary loading of cross-origin pages.

    CriticalCVSS 9.8No exploitEPSS 1%

    mozilla · firefoxOct 1, 2024

All vulnerability classes