CWE-346 · 692 kayıt
Origin Validation Error
Bu sınıftaki CVE’ler
693 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2025-34291Silahlaştırılmış | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCElangflow · langflow · CWE-346 | Kritik9,4 | KEV | %92,8 | 5 Ara 2025 |
86Hemen | CVE-2015-4495Silahlaştırılmış | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | Yüksek8,8 | KEV | %68,6 | 7 Ağu 2015 |
60Bu hafta | CVE-2023-29711İstismar yok | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via craftedinterlink · psg-5124 firmware · CWE-346 | Kritik9,8 | — | %70,3 | 22 Haz 2023 |
55Planlayın | CVE-2020-16952Silahlaştırılmış | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint enterprise server · CWE-346 | Yüksek8,6 | — | %71,1 | 16 Eki 2020 |
55Planlayın | CVE-2024-23898Kavram kanıtı | Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests majenkins · jenkins · CWE-346 | Yüksek8,8 | — | %67,2 | 24 Oca 2024 |
52Planlayın | CVE-2009-1185Silahlaştırılmış | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senudev project · udev · CWE-346 | Yüksek7,2 | — | %80,4 | 17 Nis 2009 |
41Planlayın | CVE-2000-1218İstismar yok | The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to microsoft · windows 2000 · CWE-346 | Kritik9,8 | — | %6,3 | 14 Nis 2000 |
41Planlayın | CVE-2019-3980Kavram kanıtı | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executablsolarwinds · dameware mini remote control · CWE-346 | Kritik9,8 | — | %5,1 | 8 Eki 2019 |
40Planlayın | CVE-2019-8069İstismar yok | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.adobe · flash player desktop runtime · CWE-346 | Kritik9,8 | — | %4,3 | 12 Eyl 2019 |
40Planlayın | CVE-2018-15723İstismar yok | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.logitech · harmony hub firmware · CWE-346 | Kritik9,8 | — | %3,7 | 20 Ara 2018 |
40Planlayın | CVE-2023-33443İstismar yok | Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrbesder · videoplaytool · CWE-346 | Kritik9,8 | — | %3,5 | 8 Haz 2023 |
40Planlayın | CVE-2026-42901İstismar yok | Microsoft Entra ID Elevation of Privilege Vulnerabilitymicrosoft · entra id · CWE-346 | Kritik10,0 | — | %0,5 | 22 May 2026 |
40Planlayın | CVE-2023-30856İstismar yok | eDEX-UI cross-site websocket hijacking vulnerability enables remote command executionedex-ui project · edex-ui · CWE-346 | Kritik10,0 | — | %0,3 | 28 Nis 2023 |
39İzleyin | CVE-2021-26291Kavram kanıtı | block repositories using http by defaultapache · maven · CWE-346 | Kritik9,1 | — | %8,7 | 23 Nis 2021 |
39İzleyin | CVE-2022-41924Kavram kanıtı | Tailscale Windows daemon is vulnerable to RCE via CSRFtailscale · tailscale · CWE-346 | Kritik9,6 | — | %1,8 | 23 Kas 2022 |
39İzleyin | CVE-2019-16517İstismar yok | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-346 | Kritik9,8 | — | %1,3 | 23 Oca 2020 |
39İzleyin | CVE-2018-5116İstismar yok | WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.mozilla · firefox · CWE-346 | Kritik9,8 | — | %1,2 | 11 Haz 2018 |
39İzleyin | CVE-2003-0174İstismar yok | The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP ssgi · irix · CWE-346 | Kritik9,8 | — | %1,0 | 12 May 2003 |
39İzleyin | CVE-2020-26527Kavram kanıtı | An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.damstratechnology · smart asset · CWE-346 | Kritik9,8 | — | %0,9 | 2 Eki 2020 |
39İzleyin | CVE-2019-15020İstismar yok | A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softwzingbox · inspector · CWE-346 | Kritik9,8 | — | %0,9 | 9 Eki 2019 |
39İzleyin | CVE-2017-20146İstismar yok | Improper access control in github.com/gorilla/handlersgorillatoolkit · handlers · CWE-346 | Kritik9,8 | — | %0,7 | 27 Ara 2022 |
39İzleyin | CVE-2024-25124İstismar yok | Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentialsgofiber · fiber · CWE-346 | Kritik9,8 | — | %0,7 | 21 Şub 2024 |
39İzleyin | CVE-2022-23764İstismar yok | TERUTEN WebCube update remote code execution vulnerabilityteruten · webcube · CWE-346 | Kritik9,8 | — | %0,7 | 17 Ağu 2022 |
39İzleyin | CVE-2023-29728İstismar yok | The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privapplika · call blocker · CWE-346 | Kritik9,8 | — | %0,6 | 30 May 2023 |
39İzleyin | CVE-2024-9392İstismar yok | A compromised content process could have allowed for the arbitrary loading of cross-origin pages.mozilla · firefox · CWE-346 | Kritik9,8 | — | %0,5 | 1 Eki 2024 |
- CVE-2025-3429195Hemen
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
KritikCVSS 9,4KEVSilahlaştırılmışEPSS %93langflow · langflow5 Ara 2025
- CVE-2015-449586Hemen
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69mozilla · firefox7 Ağu 2015
- CVE-2023-2971160Bu hafta
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted
KritikCVSS 9,8İstismar yokEPSS %70interlink · psg-5124 firmware22 Haz 2023
- CVE-2020-1695255Planlayın
Microsoft SharePoint Remote Code Execution Vulnerability
YüksekCVSS 8,6SilahlaştırılmışEPSS %71microsoft · sharepoint enterprise server16 Eki 2020
- CVE-2024-2389855Planlayın
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests ma
YüksekCVSS 8,8Kavram kanıtıEPSS %67jenkins · jenkins24 Oca 2024
- CVE-2009-118552Planlayın
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen
YüksekCVSS 7,2SilahlaştırılmışEPSS %80udev project · udev17 Nis 2009
- CVE-2000-121841Planlayın
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to
KritikCVSS 9,8İstismar yokEPSS %6microsoft · windows 200014 Nis 2000
- CVE-2019-398041Planlayın
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executabl
KritikCVSS 9,8Kavram kanıtıEPSS %5solarwinds · dameware mini remote control8 Eki 2019
- CVE-2019-806940Planlayın
Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4adobe · flash player desktop runtime12 Eyl 2019
- CVE-2018-1572340Planlayın
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
KritikCVSS 9,8İstismar yokEPSS %4logitech · harmony hub firmware20 Ara 2018
- CVE-2023-3344340Planlayın
Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitr
KritikCVSS 9,8İstismar yokEPSS %4besder · videoplaytool8 Haz 2023
- CVE-2026-4290140Planlayın
Microsoft Entra ID Elevation of Privilege Vulnerability
KritikCVSS 10,0İstismar yokEPSS %0microsoft · entra id22 May 2026
- CVE-2023-3085640Planlayın
eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
KritikCVSS 10,0İstismar yokEPSS %0edex-ui project · edex-ui28 Nis 2023
- CVE-2021-2629139İzleyin
block repositories using http by default
KritikCVSS 9,1Kavram kanıtıEPSS %9apache · maven23 Nis 2021
- CVE-2022-4192439İzleyin
Tailscale Windows daemon is vulnerable to RCE via CSRF
KritikCVSS 9,6Kavram kanıtıEPSS %2tailscale · tailscale23 Kas 2022
- CVE-2019-1651739İzleyin
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
KritikCVSS 9,8İstismar yokEPSS %1connectwise · control23 Oca 2020
- CVE-2018-511639İzleyin
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.
KritikCVSS 9,8İstismar yokEPSS %1mozilla · firefox11 Haz 2018
- CVE-2003-017439İzleyin
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP s
KritikCVSS 9,8İstismar yokEPSS %1sgi · irix12 May 2003
- CVE-2020-2652739İzleyin
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.
KritikCVSS 9,8Kavram kanıtıEPSS %1damstratechnology · smart asset2 Eki 2020
- CVE-2019-1502039İzleyin
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw
KritikCVSS 9,8İstismar yokEPSS %1zingbox · inspector9 Eki 2019
- CVE-2017-2014639İzleyin
Improper access control in github.com/gorilla/handlers
KritikCVSS 9,8İstismar yokEPSS %1gorillatoolkit · handlers27 Ara 2022
- CVE-2024-2512439İzleyin
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
KritikCVSS 9,8İstismar yokEPSS %1gofiber · fiber21 Şub 2024
- CVE-2022-2376439İzleyin
TERUTEN WebCube update remote code execution vulnerability
KritikCVSS 9,8İstismar yokEPSS %1teruten · webcube17 Ağu 2022
- CVE-2023-2972839İzleyin
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of priv
KritikCVSS 9,8İstismar yokEPSS %1applika · call blocker30 May 2023
- CVE-2024-939239İzleyin
A compromised content process could have allowed for the arbitrary loading of cross-origin pages.
KritikCVSS 9,8İstismar yokEPSS %1mozilla · firefox1 Eki 2024