The product does not properly verify that the source of data or communication is valid.
556 vulnerabilities with CWE-346
CVE-2023-27944
HIGH
macOS < 11.7.5 - Sandbox Escape via Entitlement Bypass
CVSS 8.6
CVE-2023-27932
MEDIUM
Safari < 16.4 - Same Origin Policy Bypass via Malicious Web Content
CVSS 5.5
CVE-2023-29868
MEDIUM
Zammad 5.3.0-5.3.x - Authenticated Incorrect Access Control
CVSS 6.5
CVE-2023-29867
MEDIUM
Zammad 5.3.0-5.3.x - Authenticated Incorrect Access Control via Zammad API
CVSS 6.5
CVE-2023-2445
MEDIUM
Devolutions Server < 2023.1.3.0 - Authenticated Improper Access Control in Subscriptions Folder Path Filter
CVSS 4.9
CVE-2023-30856
HIGH
eDEX-UI < 2.2.8 - Cross-Site WebSocket Hijacking via Terminal Control WebSocket
CVSS 8.3
CVE-2023-26114
HIGH
code-server <4.10.1 - Info Disclosure
CVSS 8.2
CVE-2023-0957
HIGH
Gitpod < 2022.11.2 - Cross-Site WebSocket Hijacking via Origin Header Misvalidation
CVSS 8.2
CVE-2023-0132
MEDIUM
Google Chrome < 109.0.5414.74 - Permission Prompt Bypass via Crafted HTML Page
CVSS 6.5
CVE-2023-22899
MEDIUM
zip4j < 2.11.2 - Origin Validation Error in ZIP Archive Decryption
CVSS 5.9
CVE-2022-50975
HIGH
Device <unknown> - Privilege Escalation
CVSS 8.8
CVE-2022-50925
CRITICAL
Prowise Reflect <1.0.9 - Code Injection
CVSS 9.8
CVE-2022-21505
MEDIUM
Oracle Linux - Lockdown Bypass via IMA Appraisal Log Mode
CVSS 6.7
CVE-2022-32144
HIGH
Huawei CV81-WDM Firmware - Denial of Service via Insufficient Input Verification
CVSS 8.6
CVE-2022-4917
MEDIUM
Google Chrome < 103.0.5060.53 - Origin Validation Error via Notification UI Spoofing
CVSS 4.3
CVE-2022-46718
MEDIUM
iPadOS < 15.7.2 - Unauthorized Sensitive Location Information Access
CVSS 5.5
CVE-2022-42860
MEDIUM
macOS 11.0.0-11.7.0 - Unauthorized File System Modification
CVSS 5.5
CVE-2022-45139
MEDIUM
WAGO PFC100, PFC200, 751-9301, 752-8303/8000-002, Touch Panel 600 Firmware 16-21 - CORS Misconfiguration
CVSS 5.3
CVE-2022-42927
HIGH
Firefox < 106 and Firefox ESR < 102.4 - Same-Origin Policy Violation via performance.getEntries()
CVSS 8.1
CVE-2022-38472
MEDIUM
Thunderbird <102.2-Firefox <104 - CSRF
CVSS 6.5
CVE-2022-29915
MEDIUM
Firefox < 100.0 - Origin Validation Error via Performance API
CVSS 4.3
CVE-2022-22757
MEDIUM
Firefox < 97.0 - Remote Browser Control via WebDriver Host Header Spoofing
CVSS 6.5
CVE-2022-1520
MEDIUM
Thunderbird < 91.9 - Origin Validation Error in Attached Message Security Status Display
CVSS 4.3
CVE-2022-41961
MEDIUM
BigBlueButton < 2.4-rc-6 - Ineffective User Ban Enforcement via Shared extId
CVSS 4.3
CVE-2022-41924
CRITICAL
Tailscale < 1.32.3 - Remote Code Execution via Local API Host Header Spoofing
CVSS 9.6
Details
Vulnerabilities
556