VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (785)

page 14 of 40
  • CVE-2025-14279HigJan 12, 2026
    risk 0.46cvss 8.1epss 0.00

    MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against…

  • CVE-2025-59845HigSep 26, 2025
    risk 0.46cvss 8.2epss 0.00

    Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability…

  • CVE-2024-10956HigMar 20, 2025
    risk 0.46cvss 7.1epss 0.00

    GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized…

  • CVE-2024-2419HigApr 17, 2024
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to the theft of an access token, making it possible for the attacker to impersonate other users. It is very similar to…

  • CVE-2023-29745HigMay 31, 2023
    risk 0.46cvss 7.1epss 0.00

    An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

  • CVE-2023-26114HigMar 23, 2023
    risk 0.46cvss 8.2epss 0.00

    Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

  • CVE-2018-6690HigSep 18, 2018
    risk 0.46cvss 7.1epss 0.00

    Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.

  • CVE-2017-0902HigAug 31, 2017
    risk 0.46cvss 8.1epss 0.05

    RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

  • CVE-2021-41088HigSep 23, 2021
    risk 0.45cvss 8.0epss 0.01

    Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The backend does not check the origin of…

  • CVE-2026-66313MedAug 4, 2026
    risk 0.44cvss 6.8epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

  • CVE-2025-59957MedOct 9, 2025
    risk 0.44cvss 6.8epss 0.00

    An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control of the system. …

  • CVE-2025-9636HigSep 4, 2025
    risk 0.44cvss 7.9epss 0.00

    pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.

  • CVE-2025-23117MedMar 1, 2025
    risk 0.44cvss 6.8epss 0.00

    An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.

  • CVE-2022-21505MedDec 24, 2024
    risk 0.44cvss 6.7epss 0.00

    In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this…

  • CVE-2021-26735MedOct 23, 2023
    risk 0.44cvss 6.7epss 0.00

    The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.

  • CVE-2021-21135MedFeb 9, 2021
    risk 0.44cvss 6.5epss 0.19

    Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2009-4139MedJul 27, 2011
    risk 0.44cvss 6.8epss 0.01

    A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or…

  • CVE-2021-21136MedFeb 9, 2021
    risk 0.43cvss 6.5epss 0.04

    Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2026-58649MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-55532HigAug 25, 2026
    risk 0.42cvss 7.6epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type:…