The product does not properly verify that the source of data or communication is valid.
692 vulnerabilities with CWE-346
CVE-2021-37967
MEDIUM
Google Chrome < 94.0.4606.54 - Cross-Origin Data Leak via Background Fetch API
CVSS 4.3
CVE-2021-37966
MEDIUM
Google Chrome < 94.0.4606.54 - URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2021-30630
MEDIUM
Google Chrome <93.0.4577.82 - Info Disclosure
CVSS 4.3
CVE-2021-41088
HIGH
Elvish < 0.14.0 - Origin Validation Error in Web UI Backend
CVSS 8.0
CVE-2021-39185
CRITICAL
http4s < 0.21.27, 0.22.0-0.22.2, 0.23.0-0.23.1, 1.0.0-M1-1.0.0-M24 - Origin Validation Error in CORS Configuration
CVSS 9.1
CVE-2021-34435
HIGH
Eclipse Theia 0.3.9-1.8.1 - Remote Code Execution via Mini-Browser HTML Preview
CVSS 8.8
CVE-2021-39175
HIGH
HedgeDoc < 1.9.0 - Unauthenticated Cross-Site Scripting via Slide Mode Speaker Notes
CVSS 8.1
CVE-2021-30596
MEDIUM
Google Chrome < 92.0.4515.131 - Unauthenticated URL Spoofing via Omnibox Manipulation
CVSS 4.3
CVE-2021-39270
HIGH
Ping Identity RSA SecurID Integration Kit < 3.2 - User Impersonation via Origin Validation Error
CVSS 7.5
CVE-2021-37705
CRITICAL
OneFuzz 2.12.0-2.31.0 - Authenticated Origin Validation Error via Multi-Tenant Domain Configuration
CVSS 10.0
CVE-2021-21229
MEDIUM
Google Chrome < 90.0.4430.93 - Domain Spoofing via Download Security UI
CVSS 6.5
CVE-2021-21211
MEDIUM
Google Chrome <90.0.4430.72 - Info Disclosure
CVSS 6.5
CVE-2021-21209
MEDIUM
Google Chrome <90.0.4430.72 - Info Disclosure
CVSS 6.5
CVE-2021-31718
HIGH
npupnp < 4.1.4 - Remote Code Execution via DNS Rebinding
CVSS 8.8
CVE-2021-26291
CRITICAL
Apache Maven < 3.8.1 - Repository Origin Validation Error via POM Dependency References
CVSS 9.1
CVE-2021-28048
MEDIUM
Dvls Server <2021.1-2020.3.18 - SSRF
CVSS 6.5
CVE-2021-23986
MEDIUM
Firefox < 87.0 - Same-Origin Policy Bypass via Search Engine Favicon
CVSS 6.5
CVE-2021-21184
MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 4.3
CVE-2021-21183
MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 4.3
CVE-2021-21175
MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-21164
MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-21163
MEDIUM
Google Chrome <89.0.4389.72 - Info Disclosure
CVSS 6.5
CVE-2021-1231
MEDIUM
Nexus 9000 Series Fabric Switches - DoS
CVSS 4.7
CVE-2021-27197
HIGH
Pelco Digital Sentry Server < 7.19.67 - Arbitrary File Write via DSUtility.dll AppendToTextFile
CVSS 8.1
CVE-2021-21136
MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
692