VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (794)

page 11 of 40
  • CVE-2025-21511HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-50654HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.02

    lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

  • CVE-2024-44734HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.

  • CVE-2024-9393HigOct 1, 2024
    risk 0.49cvss 7.5epss 0.00

    An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop…

  • CVE-2024-36421HigJul 1, 2024
    risk 0.49cvss 7.5epss 0.09

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration…

  • CVE-2024-2377HigApr 30, 2024
    risk 0.49cvss 7.6epss 0.00

    A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information.

  • CVE-2023-49803HigDec 11, 2023
    risk 0.49cvss 8.6epss 0.00

    @koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0, the middleware operates in a way that if an allowed origin is not provided, it will return an `Access-Control-Allow-Origin` header with the value of the…

  • CVE-2023-29743HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

  • CVE-2023-33740HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify parameter in a warning message.

  • CVE-2023-30196HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.

  • CVE-2023-23578HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.

  • CVE-2021-39270HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.00

    In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.

  • CVE-2020-4881HigJan 19, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive…

  • CVE-2020-6881HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.01

    ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception message to the specified device, which…

  • CVE-2020-9903HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.

  • CVE-2020-14519HigSep 16, 2020
    risk 0.49cvss 7.5epss 0.01

    This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser…

  • CVE-2020-11868HigApr 17, 2020
    risk 0.49cvss 7.5epss 0.02

    ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.

  • CVE-2020-8984HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

  • CVE-2019-19019HigDec 2, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell script via HTTP, and then executes it as…

  • CVE-2019-11777HigSep 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with…