CWE-346
615 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (615)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3365 Apps OfficeProject 2016Jun 17, 2026 Jul 14, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jul 14, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. |
In Envoy before versions 1.12.6, 1.13.4, 1.14.4, and 1.15.0 when validating TLS certificates, Envoy would incorrectly allow a wildcard DNS Subject Alternative Name apply to multiple subdomains. For example, with a SAN of...Show more |
An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006. |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 May 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0. |
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into inter...Show more |
5Debian NetappNtp+2 more17All Flash Fabric Attached Storage 8300 Firmware All Flash Fabric Attached Storage 8700 FirmwareAll Flash Fabric Attached Storage A400 Firmware+14 moreJun 17, 2026 Apr 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled e...Show more |
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header. |
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replac...Show more |
2Adobe Cardgate2Cardgate Payments MagentoJun 17, 2026 Feb 25, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotel...Show more |
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-For...Show more |
1Microsoft 1Office Online Server Jun 17, 2026 Feb 11, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'. |
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript runnin...Show more |
1Microsoft 1Office Online Server Jun 17, 2026 Jan 14, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firef...Show more |
1Openlambda Project 1Openlambda Jun 17, 2026 Jan 3, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000. |
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can tri...Show more |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreJun 17, 2026 Dec 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another...Show more |
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another...Show more |