CWE-346
746 CVEs • Abstraction: Class
Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
CVEs (746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Adobe Cardgate2Cardgate Payments MagentoJun 17, 2026 Feb 25, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotel...Show more |
IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-For...Show more |
1Microsoft 1Office Online Server Jun 17, 2026 Feb 11, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'. |
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript runnin...Show more |
1Microsoft 1Office Online Server Jun 17, 2026 Jan 14, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firef...Show more |
1Openlambda Project 1Openlambda Jun 17, 2026 Jan 3, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000. |
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can tri...Show more |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreJun 17, 2026 Dec 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another...Show more |
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another...Show more |
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which d...Show more |
1Huawei 4Hisuite Firmware Mate 20 FirmwareP30 Firmware+1 moreJun 17, 2026 Nov 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more |
1Huawei 4Hisuite Firmware Mate 20 FirmwareP30 Firmware+1 moreJun 17, 2026 Nov 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1...Show more |
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
1Microsoft 1Office Online Server Jun 17, 2026 Nov 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more |
1Microsoft 1Office Online Server Jun 17, 2026 Nov 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-144...Show more |
1Microsoft 1Sharepoint Server Jun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft...Show more |
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. |
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection...Show more |