The product does not properly verify that the source of data or communication is valid.
692 vulnerabilities with CWE-346
CVE-2023-28349
HIGH
Faronics Insight 10.0.19045 - Origin Validation Error
CVSS 8.8
CVE-2023-29743
HIGH
BestWeather 7.3.1 - Denial of Service via Database Manipulation
CVSS 7.5
CVE-2023-29728
CRITICAL
Call Blocker 6.6.3 - Origin Validation Error
CVSS 9.8
CVE-2023-33740
HIGH
luowice 3.5.18 - Unauthenticated Cloud Source Code Exposure via Warning Message Verify Parameter
CVSS 7.5
CVE-2023-23561
MEDIUM
Stormshield Endpoint Security 2.3.0-2.3.2 - Authenticated Sensitive Information Exposure via Incorrect Access Control
CVSS 5.5
CVE-2023-30196
HIGH
salesbooster <= 1.10.4 - Path Traversal via Download Endpoint
CVSS 7.5
CVE-2023-2886
MEDIUM
CBOT Chatbot <4.0.3.4-4.0.3.7 - Content Spoofing
CVSS 4.3
CVE-2023-32993
MEDIUM
Jenkins SAML Single Sign On Plugin < 2.0.2 - Insufficient Verification of Data Authenticity via SAML Metadata Retrieval
CVSS 4.8
CVE-2023-23578
HIGH
SkyBridge MB-A200 Firmware <= 01.00.05 - Unauthenticated Improper Access Control via ADB Port
CVSS 7.5
CVE-2023-28318
MEDIUM
Rocket.Chat - Message Deletion Bypass via Message Hiding
CVSS 5.3
CVE-2023-27962
MEDIUM
macOS 11.0-11.7.4 - Unprotected User Data Exposure via Path Handling Issue
CVSS 5.5
CVE-2023-27944
HIGH
macOS < 11.7.5 - Sandbox Escape via Entitlement Bypass
CVSS 8.6
CVE-2023-27932
MEDIUM
Safari < 16.4 - Same Origin Policy Bypass via Malicious Web Content
CVSS 5.5
CVE-2023-29868
MEDIUM
Zammad 5.3.0-5.3.x - Authenticated Incorrect Access Control
CVSS 6.5
CVE-2023-29867
MEDIUM
Zammad 5.3.0-5.3.x - Authenticated Incorrect Access Control via Zammad API
CVSS 6.5
CVE-2023-2445
MEDIUM
Devolutions Server < 2023.1.3.0 - Authenticated Improper Access Control in Subscriptions Folder Path Filter
CVSS 4.9
CVE-2023-30856
HIGH
eDEX-UI < 2.2.8 - Cross-Site WebSocket Hijacking via Terminal Control WebSocket
CVSS 8.3
CVE-2023-26114
HIGH
code-server <4.10.1 - Info Disclosure
CVSS 8.2
CVE-2023-0957
HIGH
Gitpod < 2022.11.2 - Cross-Site WebSocket Hijacking via Origin Header Misvalidation
CVSS 8.2
CVE-2023-0132
MEDIUM
Google Chrome < 109.0.5414.74 - Permission Prompt Bypass via Crafted HTML Page
CVSS 6.5
CVE-2023-22899
MEDIUM
zip4j < 2.11.2 - Origin Validation Error in ZIP Archive Decryption
CVSS 5.9
CVE-2022-50975
HIGH
Device <unknown> - Privilege Escalation
CVSS 8.8
CVE-2022-50925
CRITICAL
Prowise Reflect <1.0.9 - Code Injection
CVSS 9.8
CVE-2022-21505
MEDIUM
Oracle Linux - Lockdown Bypass via IMA Appraisal Log Mode
CVSS 6.7
CVE-2022-32144
HIGH
Huawei CV81-WDM Firmware - Denial of Service via Insufficient Input Verification
CVSS 8.6
Details
Vulnerabilities
692