Перейти к содержимому
Noroxi

CWE-346 · 692 записей

Origin Validation Error

CVE этого класса

693 записей

  • CVE-2025-34291
    95Срочно

    Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

    КритическаяCVSS 9,4KEVГотовый эксплойтEPSS 93 %

    langflow · langflow5 дек. 2025 г.

  • CVE-2015-4495
    86Срочно

    The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %

    mozilla · firefox7 авг. 2015 г.

  • CVE-2023-29711
    60На этой неделе

    An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted

    КритическаяCVSS 9,8Эксплойта нетEPSS 70 %

    interlink · psg-5124 firmware22 июн. 2023 г.

  • CVE-2020-16952
    55В плане

    Microsoft SharePoint Remote Code Execution Vulnerability

    ВысокаяCVSS 8,6Готовый эксплойтEPSS 71 %

    microsoft · sharepoint enterprise server16 окт. 2020 г.

  • CVE-2024-23898
    55В плане

    Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests ma

    ВысокаяCVSS 8,8Proof of conceptEPSS 67 %

    jenkins · jenkins24 янв. 2024 г.

  • CVE-2009-1185
    52В плане

    udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen

    ВысокаяCVSS 7,2Готовый эксплойтEPSS 80 %

    udev project · udev17 апр. 2009 г.

  • CVE-2000-1218
    41В плане

    The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    microsoft · windows 200014 апр. 2000 г.

  • CVE-2019-3980
    41В плане

    The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executabl

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    solarwinds · dameware mini remote control8 окт. 2019 г.

  • CVE-2019-8069
    40В плане

    Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    adobe · flash player desktop runtime12 сент. 2019 г.

  • CVE-2018-15723
    40В плане

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    logitech · harmony hub firmware20 дек. 2018 г.

  • CVE-2023-33443
    40В плане

    Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitr

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    besder · videoplaytool8 июн. 2023 г.

  • CVE-2026-42901
    40В плане

    Microsoft Entra ID Elevation of Privilege Vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    microsoft · entra id22 мая 2026 г.

  • CVE-2023-30856
    40В плане

    eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    edex-ui project · edex-ui28 апр. 2023 г.

  • CVE-2021-26291
    39Наблюдать

    block repositories using http by default

    КритическаяCVSS 9,1Proof of conceptEPSS 9 %

    apache · maven23 апр. 2021 г.

  • CVE-2022-41924
    39Наблюдать

    Tailscale Windows daemon is vulnerable to RCE via CSRF

    КритическаяCVSS 9,6Proof of conceptEPSS 2 %

    tailscale · tailscale23 нояб. 2022 г.

  • CVE-2019-16517
    39Наблюдать

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    connectwise · control23 янв. 2020 г.

  • CVE-2018-5116
    39Наблюдать

    WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mozilla · firefox11 июн. 2018 г.

  • CVE-2003-0174
    39Наблюдать

    The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP s

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sgi · irix12 мая 2003 г.

  • CVE-2020-26527
    39Наблюдать

    An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    damstratechnology · smart asset2 окт. 2020 г.

  • CVE-2019-15020
    39Наблюдать

    A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zingbox · inspector9 окт. 2019 г.

  • CVE-2017-20146
    39Наблюдать

    Improper access control in github.com/gorilla/handlers

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gorillatoolkit · handlers27 дек. 2022 г.

  • CVE-2024-25124
    39Наблюдать

    Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gofiber · fiber21 февр. 2024 г.

  • CVE-2022-23764
    39Наблюдать

    TERUTEN WebCube update remote code execution vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    teruten · webcube17 авг. 2022 г.

  • CVE-2023-29728
    39Наблюдать

    The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of priv

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    applika · call blocker30 мая 2023 г.

  • CVE-2024-9392
    39Наблюдать

    A compromised content process could have allowed for the arbitrary loading of cross-origin pages.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mozilla · firefox1 окт. 2024 г.

Все классы уязвимостей