CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

692 vulnerabilities with CWE-346
CVE-2023-28349 HIGH
Faronics Insight 10.0.19045 - Origin Validation Error
CVSS 8.8
CVE-2023-29743 HIGH
BestWeather 7.3.1 - Denial of Service via Database Manipulation
CVSS 7.5
CVE-2023-29728 CRITICAL
Call Blocker 6.6.3 - Origin Validation Error
CVSS 9.8
CVE-2023-33740 HIGH
luowice 3.5.18 - Unauthenticated Cloud Source Code Exposure via Warning Message Verify Parameter
CVSS 7.5
CVE-2023-23561 MEDIUM
Stormshield Endpoint Security 2.3.0-2.3.2 - Authenticated Sensitive Information Exposure via Incorrect Access Control
CVSS 5.5
CVE-2023-30196 HIGH
salesbooster <= 1.10.4 - Path Traversal via Download Endpoint
CVSS 7.5
CVE-2023-2886 MEDIUM
CBOT Chatbot <4.0.3.4-4.0.3.7 - Content Spoofing
CVSS 4.3
CVE-2023-32993 MEDIUM
Jenkins SAML Single Sign On Plugin < 2.0.2 - Insufficient Verification of Data Authenticity via SAML Metadata Retrieval
CVSS 4.8
CVE-2023-23578 HIGH
SkyBridge MB-A200 Firmware <= 01.00.05 - Unauthenticated Improper Access Control via ADB Port
CVSS 7.5
CVE-2023-28318 MEDIUM
Rocket.Chat - Message Deletion Bypass via Message Hiding
CVSS 5.3
CVE-2023-27962 MEDIUM
macOS 11.0-11.7.4 - Unprotected User Data Exposure via Path Handling Issue
CVSS 5.5
CVE-2023-27944 HIGH
macOS < 11.7.5 - Sandbox Escape via Entitlement Bypass
CVSS 8.6
CVE-2023-27932 MEDIUM
Safari < 16.4 - Same Origin Policy Bypass via Malicious Web Content
CVSS 5.5
CVE-2023-29868 MEDIUM
Zammad 5.3.0-5.3.x - Authenticated Incorrect Access Control
CVSS 6.5
CVE-2023-29867 MEDIUM
Zammad 5.3.0-5.3.x - Authenticated Incorrect Access Control via Zammad API
CVSS 6.5
CVE-2023-2445 MEDIUM
Devolutions Server < 2023.1.3.0 - Authenticated Improper Access Control in Subscriptions Folder Path Filter
CVSS 4.9
CVE-2023-30856 HIGH
eDEX-UI < 2.2.8 - Cross-Site WebSocket Hijacking via Terminal Control WebSocket
CVSS 8.3
CVE-2023-26114 HIGH
code-server <4.10.1 - Info Disclosure
CVSS 8.2
CVE-2023-0957 HIGH
Gitpod < 2022.11.2 - Cross-Site WebSocket Hijacking via Origin Header Misvalidation
CVSS 8.2
CVE-2023-0132 MEDIUM
Google Chrome < 109.0.5414.74 - Permission Prompt Bypass via Crafted HTML Page
CVSS 6.5
CVE-2023-22899 MEDIUM
zip4j < 2.11.2 - Origin Validation Error in ZIP Archive Decryption
CVSS 5.9
CVE-2022-50975 HIGH
Device <unknown> - Privilege Escalation
CVSS 8.8
CVE-2022-50925 CRITICAL
Prowise Reflect <1.0.9 - Code Injection
CVSS 9.8
CVE-2022-21505 MEDIUM
Oracle Linux - Lockdown Bypass via IMA Appraisal Log Mode
CVSS 6.7
CVE-2022-32144 HIGH
Huawei CV81-WDM Firmware - Denial of Service via Insufficient Input Verification
CVSS 8.6
Details
Vulnerabilities 692