The product does not properly verify that the source of data or communication is valid.
556 vulnerabilities with CWE-346
CVE-2026-22030
MEDIUM
React Router 7.0.0-7.11.0 and Remix Server Runtime < 2.17.3 - Cross-Site Request Forgery via Document POST Requests
CVSS 6.5
CVE-2026-20893
HIGH
Fujitsu Security Solution AuthConductor Client Basic V2 <2.0.25.0 -...
CVSS 7.8
CVE-2025-66593
MEDIUM
Synology Assistant < 7.0.6-50085 - Origin Validation Error
CVSS 6.1
CVE-2025-66592
MEDIUM
Synology Active Backup For Business Agent < 3.1.0-4967 - Origin Validation Error
CVSS 6.1
CVE-2025-13593
MEDIUM
Synology ActiveProtect Agent < 1.1.0-0439 - Origin Validation Error
CVSS 6.1
CVE-2025-71217
HIGH
Trend Micro Apex One (Mac) - Privilege Escalation via Self-Protection Mechanism Origin Validation Error
CVSS 7.8
CVE-2025-71214
HIGH
Trend Micro Apex One (Mac) - Privilege Escalation via iCore Service Origin Validation Error
CVSS 7.8
CVE-2025-71213
HIGH
TrendAI Apex One 2019-14.0.0.14136 & SaaS-14.0.20315 Privilege Escalation via Origin Validation Error
CVSS 7.8
CVE-2025-68467
LOW
Dark Reader - Info Disclosure
CVSS 3.4
CVE-2025-1787
MEDIUM
Genetec Update Service - Privilege Escalation
CVSS 4.2
CVE-2025-7659
HIGH
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
CVSS 8.0
CVE-2025-14279
HIGH
MLFlow <= 3.4.0 - DNS Rebinding Attack via Missing Origin Header Validation
CVSS 8.1
CVE-2025-67825
MEDIUM
Nitro PDF Pro < 14.42.0.34 - Origin Validation Error in Signer Information Display
CVSS 5.5
CVE-2025-69260
HIGH
Trend Micro Apex Central - Unauthenticated Denial of Service via Message Out-of-Bounds Read
CVSS 7.5
CVE-2025-69259
HIGH
Trend Micro Apex Central - Unauthenticated Denial of Service via NULL Return Value
CVSS 7.5
CVE-2025-69258
CRITICAL
Trend Micro Apex Central - Unauthenticated Remote Code Execution via LoadLibraryEX DLL Hijacking
CVSS 9.8
CVE-2025-69235
HIGH
Whale < 4.35.351.12 - Same-Origin Policy Bypass in Sidebar Environment
CVSS 7.5
CVE-2025-61740
HIGH
Johnson Controls IQ Panels 2/2+/IQHub/IQPanel 4/PowerG - DoS & Config Mod via Unverified Packet
CVE-2025-63388
CRITICAL
Dify v1.9.1 - Origin Validation Error in /console/api/system-features Endpoint
CVSS 9.1
CVE-2025-63386
CRITICAL
Dify v1.9.1 - Origin Validation Error in /console/api/setup Endpoint
CVSS 9.1
CVE-2025-14331
MEDIUM
Firefox < 115.31.0, < 146.0 and Thunderbird < 140.6.0, < 146.0 - Same-Origin Policy Bypass in Request Handling
CVSS 6.5
CVE-2025-34291
HIGH
KEV
Langflow <= 1.6.9 - Account Takeover and Remote Code Execution via CORS Misconfiguration
CVSS 8.8
CVE-2025-8074
MEDIUM
Synology BeeDrive < 1.4.3-13973 - Arbitrary File Write via Origin Validation Error
CVSS 5.6
CVE-2025-13947
HIGH
WebKitGTK < 2.50.3 - Information Disclosure via File Drag-and-Drop Origin Validation Error
CVSS 7.4
CVE-2025-37734
MEDIUM
Kibana Observability AI Assistant - Forged Origin Server-Side Request Forgery
CVSS 4.3
Details
Vulnerabilities
556