İçeriğe atla
Noroxi

CWE-346 · 692 kayıt

Origin Validation Error

Bu sınıftaki CVE’ler

693 kayıt

  • Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

    KritikCVSS 9,4KEVSilahlaştırılmışEPSS %93

    langflow · langflow5 Ara 2025

  • The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69

    mozilla · firefox7 Ağu 2015

  • CVE-2023-29711
    60Bu hafta

    An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted

    KritikCVSS 9,8İstismar yokEPSS %70

    interlink · psg-5124 firmware22 Haz 2023

  • CVE-2020-16952
    55Planlayın

    Microsoft SharePoint Remote Code Execution Vulnerability

    YüksekCVSS 8,6SilahlaştırılmışEPSS %71

    microsoft · sharepoint enterprise server16 Eki 2020

  • CVE-2024-23898
    55Planlayın

    Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests ma

    YüksekCVSS 8,8Kavram kanıtıEPSS %67

    jenkins · jenkins24 Oca 2024

  • CVE-2009-1185
    52Planlayın

    udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen

    YüksekCVSS 7,2SilahlaştırılmışEPSS %80

    udev project · udev17 Nis 2009

  • CVE-2000-1218
    41Planlayın

    The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to

    KritikCVSS 9,8İstismar yokEPSS %6

    microsoft · windows 200014 Nis 2000

  • CVE-2019-3980
    41Planlayın

    The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executabl

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    solarwinds · dameware mini remote control8 Eki 2019

  • CVE-2019-8069
    40Planlayın

    Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %4

    adobe · flash player desktop runtime12 Eyl 2019

  • CVE-2018-15723
    40Planlayın

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.

    KritikCVSS 9,8İstismar yokEPSS %4

    logitech · harmony hub firmware20 Ara 2018

  • CVE-2023-33443
    40Planlayın

    Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitr

    KritikCVSS 9,8İstismar yokEPSS %4

    besder · videoplaytool8 Haz 2023

  • CVE-2026-42901
    40Planlayın

    Microsoft Entra ID Elevation of Privilege Vulnerability

    KritikCVSS 10,0İstismar yokEPSS %0

    microsoft · entra id22 May 2026

  • CVE-2023-30856
    40Planlayın

    eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution

    KritikCVSS 10,0İstismar yokEPSS %0

    edex-ui project · edex-ui28 Nis 2023

  • CVE-2021-26291
    39İzleyin

    block repositories using http by default

    KritikCVSS 9,1Kavram kanıtıEPSS %9

    apache · maven23 Nis 2021

  • CVE-2022-41924
    39İzleyin

    Tailscale Windows daemon is vulnerable to RCE via CSRF

    KritikCVSS 9,6Kavram kanıtıEPSS %2

    tailscale · tailscale23 Kas 2022

  • CVE-2019-16517
    39İzleyin

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    KritikCVSS 9,8İstismar yokEPSS %1

    connectwise · control23 Oca 2020

  • CVE-2018-5116
    39İzleyin

    WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin.

    KritikCVSS 9,8İstismar yokEPSS %1

    mozilla · firefox11 Haz 2018

  • CVE-2003-0174
    39İzleyin

    The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP s

    KritikCVSS 9,8İstismar yokEPSS %1

    sgi · irix12 May 2003

  • CVE-2020-26527
    39İzleyin

    An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7.

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    damstratechnology · smart asset2 Eki 2020

  • CVE-2019-15020
    39İzleyin

    A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid softw

    KritikCVSS 9,8İstismar yokEPSS %1

    zingbox · inspector9 Eki 2019

  • CVE-2017-20146
    39İzleyin

    Improper access control in github.com/gorilla/handlers

    KritikCVSS 9,8İstismar yokEPSS %1

    gorillatoolkit · handlers27 Ara 2022

  • CVE-2024-25124
    39İzleyin

    Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials

    KritikCVSS 9,8İstismar yokEPSS %1

    gofiber · fiber21 Şub 2024

  • CVE-2022-23764
    39İzleyin

    TERUTEN WebCube update remote code execution vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    teruten · webcube17 Ağu 2022

  • CVE-2023-29728
    39İzleyin

    The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of priv

    KritikCVSS 9,8İstismar yokEPSS %1

    applika · call blocker30 May 2023

  • CVE-2024-9392
    39İzleyin

    A compromised content process could have allowed for the arbitrary loading of cross-origin pages.

    KritikCVSS 9,8İstismar yokEPSS %1

    mozilla · firefox1 Eki 2024

Tüm zafiyet sınıfları