CWE-346 · 692 записей
Origin Validation Error
CVE этого класса
693 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2025-34291Готовый эксплойт | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCElangflow · langflow · CWE-346 | Критическая9,4 | KEV | 92,8 % | 5 дек. 2025 г. |
86Срочно | CVE-2015-4495Готовый эксплойт | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | Высокая8,8 | KEV | 68,6 % | 7 авг. 2015 г. |
60На этой неделе | CVE-2023-29711Эксплойта нет | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via craftedinterlink · psg-5124 firmware · CWE-346 | Критическая9,8 | — | 70,3 % | 22 июн. 2023 г. |
55В плане | CVE-2020-16952Готовый эксплойт | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-346 | Высокая8,6 | — | 71,1 % | 16 окт. 2020 г. |
55В плане | CVE-2024-23898Proof of concept | Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests majenkins · jenkins · CWE-346 | Высокая8,8 | — | 67,2 % | 24 янв. 2024 г. |
52В плане | CVE-2009-1185Готовый эксплойт | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senudev project · udev · CWE-346 | Высокая7,2 | — | 80,4 % | 17 апр. 2009 г. |
41В плане | CVE-2000-1218Эксплойта нет | The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to microsoft · windows 2000 · CWE-346 | Критическая9,8 | — | 6,3 % | 14 апр. 2000 г. |
41В плане | CVE-2019-3980Proof of concept | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executablsolarwinds · dameware mini remote control · CWE-346 | Критическая9,8 | — | 5,1 % | 8 окт. 2019 г. |
40В плане | CVE-2019-8069Эксплойта нет | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.adobe · flash player desktop runtime · CWE-346 | Критическая9,8 | — | 4,3 % | 12 сент. 2019 г. |
40В плане | CVE-2018-15723Эксплойта нет | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.logitech · harmony hub firmware · CWE-346 | Критическая9,8 | — | 3,7 % | 20 дек. 2018 г. |
40В плане | CVE-2023-33443Эксплойта нет | Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrbesder · videoplaytool · CWE-346 | Критическая9,8 | — | 3,5 % | 8 июн. 2023 г. |
40В плане | CVE-2026-42901Эксплойта нет | Microsoft Entra ID Elevation of Privilege Vulnerabilitymicrosoft · entra id · CWE-346 | Критическая10,0 | — | 0,5 % | 22 мая 2026 г. |
40В плане | CVE-2023-30856Эксплойта нет | eDEX-UI cross-site websocket hijacking vulnerability enables remote command executionedex-ui project · edex-ui · CWE-346 | Критическая10,0 | — | 0,3 % | 28 апр. 2023 г. |
39Наблюдать | CVE-2021-26291Proof of concept | block repositories using http by defaultapache · maven · CWE-346 | Критическая9,1 | — | 8,7 % | 23 апр. 2021 г. |
39Наблюдать | CVE-2022-41924Proof of concept | Tailscale Windows daemon is vulnerable to RCE via CSRFtailscale · tailscale · CWE-346 | Критическая9,6 | — | 1,8 % | 23 нояб. 2022 г. |
39Наблюдать | CVE-2019-16517Эксплойта нет | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-346 | Критическая9,8 | — | 1,3 % | 23 янв. 2020 г. |
39Наблюдать | CVE-2018-5116Эксплойта нет | WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.mozilla · firefox · CWE-346 | Критическая9,8 | — | 1,2 % | 11 июн. 2018 г. |
39Наблюдать | CVE-2003-0174Эксплойта нет | The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP ssgi · irix · CWE-346 | Критическая9,8 | — | 1,0 % | 12 мая 2003 г. |
39Наблюдать | CVE-2020-26527Proof of concept | An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.damstratechnology · smart asset · CWE-346 | Критическая9,8 | — | 0,9 % | 2 окт. 2020 г. |
39Наблюдать | CVE-2019-15020Эксплойта нет | A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softwzingbox · inspector · CWE-346 | Критическая9,8 | — | 0,9 % | 9 окт. 2019 г. |
39Наблюдать | CVE-2017-20146Эксплойта нет | Improper access control in github.com/gorilla/handlersgorillatoolkit · handlers · CWE-346 | Критическая9,8 | — | 0,7 % | 27 дек. 2022 г. |
39Наблюдать | CVE-2024-25124Эксплойта нет | Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentialsgofiber · fiber · CWE-346 | Критическая9,8 | — | 0,7 % | 21 февр. 2024 г. |
39Наблюдать | CVE-2022-23764Эксплойта нет | TERUTEN WebCube update remote code execution vulnerabilityteruten · webcube · CWE-346 | Критическая9,8 | — | 0,7 % | 17 авг. 2022 г. |
39Наблюдать | CVE-2023-29728Эксплойта нет | The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privapplika · call blocker · CWE-346 | Критическая9,8 | — | 0,6 % | 30 мая 2023 г. |
39Наблюдать | CVE-2024-9392Эксплойта нет | A compromised content process could have allowed for the arbitrary loading of cross-origin pages.mozilla · firefox · CWE-346 | Критическая9,8 | — | 0,5 % | 1 окт. 2024 г. |
- CVE-2025-3429195Срочно
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
КритическаяCVSS 9,4KEVГотовый эксплойтEPSS 93 %langflow · langflow5 дек. 2025 г.
- CVE-2015-449586Срочно
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox7 авг. 2015 г.
- CVE-2023-2971160На этой неделе
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted
КритическаяCVSS 9,8Эксплойта нетEPSS 70 %interlink · psg-5124 firmware22 июн. 2023 г.
- CVE-2020-1695255В плане
Microsoft SharePoint Remote Code Execution Vulnerability
ВысокаяCVSS 8,6Готовый эксплойтEPSS 71 %microsoft · sharepoint enterprise server16 окт. 2020 г.
- CVE-2024-2389855В плане
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests ma
ВысокаяCVSS 8,8Proof of conceptEPSS 67 %jenkins · jenkins24 янв. 2024 г.
- CVE-2009-118552В плане
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen
ВысокаяCVSS 7,2Готовый эксплойтEPSS 80 %udev project · udev17 апр. 2009 г.
- CVE-2000-121841В плане
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %microsoft · windows 200014 апр. 2000 г.
- CVE-2019-398041В плане
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executabl
КритическаяCVSS 9,8Proof of conceptEPSS 5 %solarwinds · dameware mini remote control8 окт. 2019 г.
- CVE-2019-806940В плане
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %adobe · flash player desktop runtime12 сент. 2019 г.
- CVE-2018-1572340В плане
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %logitech · harmony hub firmware20 дек. 2018 г.
- CVE-2023-3344340В плане
Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %besder · videoplaytool8 июн. 2023 г.
- CVE-2026-4290140В плане
Microsoft Entra ID Elevation of Privilege Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %microsoft · entra id22 мая 2026 г.
- CVE-2023-3085640В плане
eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %edex-ui project · edex-ui28 апр. 2023 г.
- CVE-2021-2629139Наблюдать
block repositories using http by default
КритическаяCVSS 9,1Proof of conceptEPSS 9 %apache · maven23 апр. 2021 г.
- CVE-2022-4192439Наблюдать
Tailscale Windows daemon is vulnerable to RCE via CSRF
КритическаяCVSS 9,6Proof of conceptEPSS 2 %tailscale · tailscale23 нояб. 2022 г.
- CVE-2019-1651739Наблюдать
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %connectwise · control23 янв. 2020 г.
- CVE-2018-511639Наблюдать
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox11 июн. 2018 г.
- CVE-2003-017439Наблюдать
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP s
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sgi · irix12 мая 2003 г.
- CVE-2020-2652739Наблюдать
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %damstratechnology · smart asset2 окт. 2020 г.
- CVE-2019-1502039Наблюдать
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zingbox · inspector9 окт. 2019 г.
- CVE-2017-2014639Наблюдать
Improper access control in github.com/gorilla/handlers
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gorillatoolkit · handlers27 дек. 2022 г.
- CVE-2024-2512439Наблюдать
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gofiber · fiber21 февр. 2024 г.
- CVE-2022-2376439Наблюдать
TERUTEN WebCube update remote code execution vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %teruten · webcube17 авг. 2022 г.
- CVE-2023-2972839Наблюдать
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of priv
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %applika · call blocker30 мая 2023 г.
- CVE-2024-939239Наблюдать
A compromised content process could have allowed for the arbitrary loading of cross-origin pages.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox1 окт. 2024 г.