VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (729)

page 4 of 37
  • CVE-2021-47157CriMar 18, 2024
    risk 0.57cvss 9.8epss 0.00

    The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

  • CVE-2023-32223HigJun 28, 2023
    risk 0.57cvss 8.8epss 0.02

    D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.

  • CVE-2023-27745HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.00

    An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.

  • CVE-2023-28349HigMay 31, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student…

  • CVE-2017-20146CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

  • CVE-2022-3457CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.

  • CVE-2022-22637HigSep 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.

  • CVE-2022-23764HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.01

    The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution.

  • CVE-2022-26137HigJul 20, 2022
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this…

  • CVE-2022-30228HigJun 14, 2022
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected software does not apply cross-origin resource sharing (CORS) restrictions for critical operations. In case an attacker tricks a legitimate user into accessing a special resource…

  • CVE-2022-25227HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.

  • CVE-2020-24772HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that…

  • CVE-2021-31718HigApr 25, 2021
    risk 0.57cvss 8.8epss 0.01

    The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.

  • CVE-2018-6654HigFeb 6, 2018
    risk 0.57cvss 8.8epss 0.01

    The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web site.

  • CVE-2017-8793HigMay 5, 2017
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the…

  • CVE-2026-47194HigAug 6, 2026
    risk 0.56cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point to an attacker-controlled domain and…

  • CVE-2026-47825HigJun 15, 2026
    risk 0.56cvss 8.6epss 0.00

    Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway…

  • CVE-2022-32144HigDec 20, 2024
    risk 0.56cvss 8.6epss 0.00

    There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID:…

  • CVE-2024-23898HigJan 24, 2024
    risk 0.56cvss 8.8epss 0.67

    Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute…

  • CVE-2023-27944HigMay 8, 2023
    risk 0.56cvss 8.6epss 0.00

    This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to break out of its sandbox.