CWE-346
746 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be us...Show more |
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed |
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid. |
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform...Show more |
1Apple 6Ipados Iphone OsMacos+3 moreJun 17, 2026 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to tr...Show more |
1Sysend.js Project 1Sysend.js Jun 17, 2026 Mar 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the co...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJul 9, 2026 Mar 3, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowi...Show more |
PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit events to a socket, potentially interfering with a victim's "now playing" status on Discord. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
3Debian FedoraprojectTwisted3Debian Linux FedoraTwistedJun 17, 2026 Feb 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.Redir...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientJun 17, 2026 Jan 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: So...Show more |
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal...Show more |
1Trendmicro 3Apex One Worry Free Business SecurityWorry Free Business Security ServicesJun 17, 2026 Jan 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher l...Show more |
4Aeotec FibaroSilabs+1 more6500 Series Firmware Fgwpb 111Zen20+3 moreJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fi...Show more |
3Fedoraproject Podman ProjectRedhat3Enterprise Linux FedoraPodmanJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on p...Show more |
glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attacker can complete the attack remotely without interaction. |
1Ibm 1Spectrum Protect Plus Jun 17, 2026 Dec 13, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in...Show more |