Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

626 CVEs tagged with CWE-34664 Critical, 216 High, 324 Medium, 21 Low, 1 Unrated.

CVE-2024-10956

Published Mar 20, 2025

GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an ex…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2346

Published Mar 16, 2025

A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain H…

CVSS 6.3 · Medium

CVE-2025-25306

Published Mar 10, 2025

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-25302

Published Mar 3, 2025

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cro…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23117

Published Mar 1, 2025

An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported cha…

CVSS 6.8 · Medium

CVE-2025-1102

Published Feb 12, 2025

A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1083

Published Feb 6, 2025

A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-23023

Published Feb 4, 2025

Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to poison the anonymou…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55948

Published Feb 4, 2025

Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-57965

Published Jan 29, 2025

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: so…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2025-21511

Published Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21497

Published Jan 21, 2025

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Ea…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21245

Published Jan 21, 2025

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24010

Published Jan 20, 2025

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46715

Published Jan 14, 2025

An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user wi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23109

Published Jan 11, 2025

Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55917

Published Dec 31, 2024

An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must fi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21505

Published Dec 24, 2024

In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailabl…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56170

Published Dec 18, 2024

A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everyth…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54490

Published Dec 12, 2024

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45495

Published Nov 29, 2024

MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.

CVSS 4.3 · Medium

CVE-2024-51072

Published Nov 22, 2024

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. NOTE: this is disp…

CVSS 5.3 · Medium
Showing 276-300 of 626 CVEsPage 12 of 26