← Back
CWE-346

746 CVEs • Abstraction: Class

Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

JSON object

Loading...

CVEs (746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Adobe
Cardgate
2Cardgate Payments
Magento
Jun 17, 2026
Feb 25, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotel...Show more
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.Show less
1Ibm
1Security Secret Server
Jun 17, 2026
Feb 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-For...Show more
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.Show less
1Microsoft
1Office Online Server
Jun 17, 2026
Feb 11, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'.
1Connectwise
1Control
Jun 17, 2026
Jan 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript runnin...Show more
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.Show less
1Microsoft
1Office Online Server
Jun 17, 2026
Jan 14, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'.
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firef...Show more
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.Show less
1Openlambda Project
1Openlambda
Jun 17, 2026
Jan 3, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.
1W1.fi
1Hostapd
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can tri...Show more
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.Show less
4Debian
FedoraprojectGoogle+1 more
7Chrome
Debian LinuxEnterprise Linux Desktop+4 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
1Norton
1Password Manager
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another...Show more
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.Show less
1Norton
1Password Manager
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another...Show more
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.Show less
1Titanhq
1Webtitan
Jun 17, 2026
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
8.5 HIGH· v2
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which d...Show more
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell script via HTTP, and then executes it as root. This is analogous to CVE-2019-6800 but for a different product.Show less
1Huawei
4Hisuite Firmware
Mate 20 FirmwareP30 Firmware+1 more
Jun 17, 2026
Nov 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.Show less
1Huawei
4Hisuite Firmware
Mate 20 FirmwareP30 Firmware+1 more
Jun 17, 2026
Nov 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.Show less
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
1Microsoft
1Office Online Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445.Show less
1Microsoft
1Office Online Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447.Show less
1Microsoft
1Sharepoint Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft...Show more
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.Show less
1Microsoft
1Edge
Jun 17, 2026
Nov 12, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection...Show more
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.Show less