The product does not properly verify that the source of data or communication is valid.
684 vulnerabilities with CWE-346
CVE-2026-56181
HIGH
Microsoft Windows 11 Version 24H2 - Windows Network Address Translation (NAT) Spoofing Vulnerability
CVSS 8.3
CVE-2026-15076
HIGH
Eclipse Vert.x - Origin Validation Error
CVSS 7.5
CVE-2026-15075
HIGH
Eclipse Vert.x - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.5
CVE-2026-55669
MEDIUM
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
CVSS 4.2
CVE-2026-59208
MEDIUM
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVSS 6.8
CVE-2026-59723
HIGH
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
CVSS 8.8
CVE-2026-59883
MEDIUM
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVSS 4.7
CVE-2026-55438
MEDIUM
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
CVSS 5.8
CVE-2026-59153
LOW
Anki's local HTTP server does not sufficiently validate requests
CVE-2026-58266
MEDIUM
Anki: User scripts in iframes have access to the internal Anki API
CVSS 6.5
CVE-2026-34198
MEDIUM
Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing
CVSS 5.3
CVE-2026-42341
CRITICAL
FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
CVE-2026-59152
MEDIUM
Arbitrary server-side file read in LangSmith SDK TracingMiddleware
CVSS 5.0
CVE-2026-59096
HIGH
Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forwarded-Host
CVSS 7.5
CVE-2026-55660
HIGH
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
CVE-2026-56277
MEDIUM
Flowise - Hardcoded CORS Wildcard in TTS Endpoint
CVSS 6.5
CVE-2026-14105
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via Speech Policy Enforcement
CVSS 4.3
CVE-2026-14079
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-14057
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via FedCM
CVSS 4.3
CVE-2026-14053
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Extensions Policy Bypass
CVSS 4.3
CVE-2026-14046
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via CustomTabs
CVSS 4.3
CVE-2026-14039
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via GetUserMedia
CVSS 4.3
CVE-2026-13913
MEDIUM
Google Chrome < 150.0.7871.47 - Insufficient Policy Enforcement in Autofill
CVSS 6.5
CVE-2026-13887
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via NFC Implementation
CVSS 6.5
CVE-2026-13881
MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via WebAppInstalls
CVSS 6.5
Details
Vulnerabilities
684