CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

479 vulnerabilities with CWE-346
CVE-2025-62250 MEDIUM
Liferay Digital Experience Platform < 7.3 - Origin Validation Error
CVSS 6.5
CVE-2025-62584 HIGH
Navercorp Whale < 4.33.325.17 - Origin Validation Error
CVSS 7.5
CVE-2025-9265 CRITICAL
Kiloview NDI N30 - Auth Bypass
CVE-2025-2140 MEDIUM
IBM Engineering Requirements Management Doors Next <7.1 - Auth Bypass
CVSS 5.7
CVE-2025-59957 MEDIUM
Juniper Junos < 21.4 - Origin Validation Error
CVSS 6.8
CVE-2025-42706 MEDIUM
Falcon sensor <7.24 - Privilege Escalation
CVSS 6.5
CVE-2025-59159 CRITICAL
SillyTavern <1.13.4 - SSRF
CVSS 9.6
CVE-2025-11304 MEDIUM
CodeCanyon/ui-lib Mentor LMS <1.1.1 - XSS
CVSS 6.3
CVE-2025-59845 HIGH
Apollo Sandbox < 2.7.2 - CSRF
CVSS 8.2
CVE-2025-20364 MEDIUM
Cisco Wireless AP Software - RCE
CVSS 4.3
CVE-2025-56648 MEDIUM
Parcel < 1.10.3 - Origin Validation Error
CVSS 6.5
CVE-2025-10193 HIGH
Pypi Mcp-neo4j-cypher < 0.4.0 - Origin Validation Error
CVE-2025-10201 HIGH
Google Chrome < 140.0.7339.127 - Improper Access Control
CVSS 8.8
CVE-2025-9636 HIGH
pgAdmin <= 9.7 - XSS
CVSS 7.9
CVE-2025-47909 HIGH
Gorilla Csrf - Origin Validation Error
CVSS 7.3
CVE-2025-51605 HIGH
Shopizer - Origin Validation Error
CVSS 8.1
CVE-2025-9180 HIGH
Firefox <142 - SSRF
CVSS 8.1
CVE-2025-52621 MEDIUM
Hcltech Bigfix Saas < 8.1.14 - Origin Validation Error
CVSS 5.3
CVE-2025-8881 MEDIUM
Google Chrome < 139.0.7258.127 - Origin Validation Error
CVSS 6.5
CVE-2025-53399 MEDIUM
Sipwise rtpengine <13.4.1.1 - Command Injection
CVE-2025-7365 HIGH
Redhat Keycloak < 26.0.13 - Origin Validation Error
CVSS 7.1
CVE-2025-53600 HIGH
Whale browser <4.32.315.22 - CSRF
CVSS 7.5
CVE-2025-5824 HIGH
Autel MaxiCharger AC Wallbox Commercial - Auth Bypass
CVSS 7.5
CVE-2025-42998 MEDIUM
SAP Business One Integration Framework - Auth Bypass
CVSS 5.3
CVE-2025-30360 MEDIUM
webpack-dev-server <5.2.1 - XSS
CVSS 6.5
Details
Vulnerabilities 479