Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

626 CVEs tagged with CWE-34664 Critical, 216 High, 324 Medium, 21 Low, 1 Unrated.

CVE-2023-47194

Published Jan 23, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47193

Published Jan 23, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28794

Published Nov 6, 2023

Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5718

Published Oct 23, 2023

The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By creating a malicious web page with an iFrame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28795

Published Oct 23, 2023

Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: bef…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26737

Published Oct 23, 2023

The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26735

Published Oct 23, 2023

The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYST…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3654

Published Oct 3, 2023

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2848

Published Sep 14, 2023

Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4045

Published Aug 1, 2023

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerabi…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-30949

Published Jul 26, 2023

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2850

Published Jul 25, 2023

NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user inform…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3581

Published Jul 17, 2023

Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 626 CVEsPage 15 of 26