VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (786)

page 4 of 40
  • CVE-2022-50975HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.

  • CVE-2025-10201HigSep 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-45352HigMar 27, 2025
    risk 0.57cvss 8.8epss 0.00

    An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

  • CVE-2024-53866CriDec 10, 2024
    risk 0.57cvss 9.8epss 0.01

    The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data…

  • CVE-2024-41475HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

  • CVE-2023-27360HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.00

    NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2021-47157CriMar 18, 2024
    risk 0.57cvss 9.8epss 0.00

    The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

  • CVE-2023-32223HigJun 28, 2023
    risk 0.57cvss 8.8epss 0.02

    D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.

  • CVE-2023-27745HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.00

    An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.

  • CVE-2023-28349HigMay 31, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student…

  • CVE-2017-20146CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

  • CVE-2022-3457CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.

  • CVE-2022-22637HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.

  • CVE-2022-23764HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.01

    The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution.

  • CVE-2022-26137HigJul 20, 2022
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this…

  • CVE-2022-30228HigJun 14, 2022
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimate user into accessing a special resource…

  • CVE-2022-25227HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.

  • CVE-2020-24772HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that…

  • CVE-2021-31718HigApr 25, 2021
    risk 0.57cvss 8.8epss 0.01

    The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.

  • CVE-2018-6654HigFeb 6, 2018
    risk 0.57cvss 8.8epss 0.01

    The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web site.