Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

626 CVEs tagged with CWE-34664 Critical, 216 High, 324 Medium, 21 Low, 1 Unrated.

CVE-2024-51037

Published Nov 15, 2024

An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50654

Published Nov 15, 2024

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for cou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6674

Published Oct 29, 2024

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing privat…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10460

Published Oct 29, 2024

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-44734

Published Oct 11, 2024

Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.

CVSS 7.5 · High

CVE-2024-9392

Published Oct 1, 2024

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-7978

Published Aug 21, 2024

Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41475

Published Aug 12, 2024

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23458

Published Aug 6, 2024

While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41926

Published Aug 1, 2024

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set ar…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-41143

Published Jul 29, 2024

Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SY…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22062

Published Jul 9, 2024

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5549

Published Jul 9, 2024

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36421

Published Jul 1, 2024

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25211

Published Jun 29, 2024

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention…

CVSS 9.1 · Critical

CVE-2024-6301

Published Jun 25, 2024

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5905

Published Jun 12, 2024

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-36303

Published Jun 10, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36302

Published Jun 10, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36472

Published May 28, 2024

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who…

CVSS 6.5 · Medium
Showing 301-325 of 626 CVEsPage 13 of 26