CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

556 vulnerabilities with CWE-346
CVE-2021-21211 MEDIUM
Google Chrome <90.0.4430.72 - Info Disclosure
CVSS 6.5
CVE-2021-21209 MEDIUM
Google Chrome <90.0.4430.72 - Info Disclosure
CVSS 6.5
CVE-2021-31718 HIGH
npupnp < 4.1.4 - Remote Code Execution via DNS Rebinding
CVSS 8.8
CVE-2021-26291 CRITICAL
Apache Maven < 3.8.1 - Repository Origin Validation Error via POM Dependency References
CVSS 9.1
CVE-2021-28048 MEDIUM
Dvls Server <2021.1-2020.3.18 - SSRF
CVSS 6.5
CVE-2021-23986 MEDIUM
Firefox < 87.0 - Same-Origin Policy Bypass via Search Engine Favicon
CVSS 6.5
CVE-2021-21184 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 4.3
CVE-2021-21183 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 4.3
CVE-2021-21175 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-21164 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-21163 MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-1231 MEDIUM
Nexus 9000 Series Fabric Switches - DoS
CVSS 4.7
CVE-2021-27197 HIGH
Pelco Digital Sentry Server < 7.19.67 - Arbitrary File Write via DSUtility.dll AppendToTextFile
CVSS 8.1
CVE-2021-21136 MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
CVE-2021-21135 MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
CVE-2021-20199 MEDIUM
Podman 1.8.0-3.0.0 - Origin Validation Error in Rootless Containers
CVSS 5.9
CVE-2020-24772 HIGH
Dreamacro Clash for Windows 0.11.4 - Origin Validation Error via Malicious Iframe URL
CVSS 8.8
CVE-2020-9060 MEDIUM
Silicon Labs 500 Series Firmware - Denial of Service via Malformed Z-Wave S2 Messages
CVSS 6.5
CVE-2020-27969 HIGH
Yandex Browser for Android < 20.8.4 - Same-Origin Policy Bypass and Address Bar Spoofing
CVSS 7.3
CVE-2020-15734 MEDIUM
Bitdefender Safepay < 25.0.7.29 - Origin Validation Error via File Upload Manipulation
CVSS 5.5
CVE-2020-4881 HIGH
IBM Planning Analytics 2.0 - Sensitive Information Exposure via SSL/TLS Server Hostname Verification Bypass
CVSS 7.5
CVE-2020-28481 MEDIUM
socket.io < 2.4.0 - Insecure Defaults via CORS Misconfiguration
CVSS 5.3
CVE-2020-6881 HIGH
ZTE ZXHN E8810/E8820/E8822 Firmware - Denial of Service via MQTT Message Handling
CVSS 7.5
CVE-2020-26251 MEDIUM
Open Zaak < 1.3.3 - Origin Validation Error via CORS Misconfiguration
CVSS 4.7
CVE-2020-15733 MEDIUM
Bitdefender Antivirus Plus < 25.0.7.29 - Origin Validation Error in SafePay
CVSS 6.5
Details
Vulnerabilities 556