CWE-346: CWE-346

99
Total CVEs
20
Critical
48
High
7.5
Avg CVSS

Yearly Trend

2026
13
2025
45
2024
22
2023
8
2022
5

Top Affected Vendors

1 Trendmicro 7
2 Oracle 5
3 Mozilla 4
4 Apple 2
5 Discourse 2
6 Ibm 2
7 Apache 2
8 Langgenius 2
9 Siemens 1
10 Meshcentral 1

All CWE-346 CVEs (99)

CVE-2026-28403
7.6

Textream macOS teleprompter app versions before 1.5.1 have a WebSocket server that doesn't validate the Origin header, allowing malicious web pages to...

Mar 2, 2026
CVE-2025-69235
7.5

This vulnerability allows attackers to bypass the Same-Origin Policy in Whale browser's sidebar environment, potentially enabling cross-origin data th...

Dec 30, 2025
CVE-2025-5824
7.5

This vulnerability allows attackers within Bluetooth range to bypass authentication on Autel MaxiCharger AC Wallbox Commercial electric vehicle chargi...

Jun 25, 2025
CVE-2024-8024
7.5

A CORS misconfiguration in netease-youdao/qanything version 1.4.1 allows attackers to bypass Same-Origin Policy protections, potentially exposing sens...

Mar 20, 2025
CVE-2025-21511
7.5

This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers to remotely access sensitive data via HTTP. It affects al...

Jan 21, 2025
CVE-2024-50654
7.5

This vulnerability in lilishop e-commerce platform allows attackers to bypass coupon quantity limits during high-traffic periods by intercepting and r...

Nov 15, 2024
CVE-2024-44734
7.5

This vulnerability allows attackers to change usernames arbitrarily in Mirotalk video conferencing systems by sending crafted roomAction requests. It ...

Oct 11, 2024
CVE-2024-36421
7.5

Flowise version 1.4.3 has a CORS misconfiguration that allows arbitrary origins to connect to the website, potentially enabling cross-origin attacks. ...

Jul 1, 2024
CVE-2025-13947
7.4

This vulnerability in WebKitGTK allows attackers to trick users into dragging files from their local system into a malicious webpage, which can then r...

Dec 3, 2025
CVE-2025-46737
7.4

SEL-5037 Grid Configurator contains an overly permissive CORS configuration that allows unauthorized cross-origin requests to its data gateway API. Th...

May 12, 2025
CVE-2024-7819
7.4

A CORS misconfiguration in Danswer AI v1.4.1 allows malicious websites to make unauthorized cross-origin requests to the application's API, potentiall...

Mar 20, 2025
CVE-2024-11602
7.4

A CORS misconfiguration in feast-dev/feast version 0.40.0 allows any external domain to make requests to the agentscope server API, bypassing intended...

Mar 20, 2025
CVE-2024-28883
7.4

An origin validation vulnerability in BIG-IP APM browser network access VPN client allows attackers to bypass F5 endpoint inspection. This affects Win...

May 8, 2024
CVE-2024-13068
7.3

This CVE describes an origin validation error in Akinsoft LimonDesk that allows forceful browsing attacks. Attackers can bypass intended access contro...

Sep 3, 2025
CVE-2025-47909
7.3

This CVE describes a CSRF vulnerability in Go applications using TrustedOrigins where network attackers can bypass same-origin checks. Applications th...

Aug 29, 2025
CVE-2021-46701
7.2

CVE-2021-46701 is a WebSocket transport vulnerability in PreMiD 2.2.0 that allows unauthorized access to socket events. Attackers can intercept and ma...

Feb 20, 2022
CVE-2024-10956
7.1

CVE-2024-10956 is a Cross-Site WebSocket Hijacking vulnerability in GPT Academy version 3.83 that allows attackers to hijack WebSocket connections bet...

Mar 20, 2025
CVE-2024-6674
7.1

A CORS misconfiguration in lollms-webui allows attackers to steal sensitive information like logs, browser sessions, and settings containing private A...

Oct 29, 2024
CVE-2025-59957
6.8

An origin validation error in Juniper EX4600 and QFX5000 Series devices allows attackers with physical access to create persistent backdoors when no r...

Oct 9, 2025
CVE-2025-23117
6.8

This vulnerability allows authenticated attackers on the same network as UniFi Protect Cameras to bypass firmware validation and make unauthorized sys...

Mar 1, 2025
CVE-2022-21505
6.7

This vulnerability in the Linux kernel allows bypassing lockdown mode when IMA appraisal is configured with 'ima_appraise=log' boot parameter and Secu...

Dec 24, 2024
CVE-2026-22030
6.5

This CVE describes a CSRF vulnerability in React Router and Remix that allows attackers to trick authenticated users into submitting malicious POST re...

Jan 10, 2026
CVE-2025-14331
6.5

This CVE describes a same-origin policy bypass vulnerability in Firefox and Thunderbird's request handling component. It allows malicious websites to ...

Dec 9, 2025
CVE-2025-42706
6.5

A logic error in CrowdStrike Falcon sensor for Windows allows attackers with existing code execution on a host to delete arbitrary files. Only Windows...

Oct 8, 2025
CVE-2025-56648
6.5

CVE-2025-56648 is an Origin Validation Error vulnerability in Parcel development servers that allows malicious websites to make cross-origin requests ...

Sep 17, 2025
CVE-2025-30360
6.5

Webpack-dev-server versions before 5.2.1 have a Cross-Site WebSocket Hijacking vulnerability that allows malicious websites to steal source code from ...

Jun 3, 2025
CVE-2026-22694
6.1

This vulnerability in AliasVault Android app allows a malicious local app to potentially obtain passkey responses for websites it shouldn't have acces...

Jan 14, 2026
CVE-2025-2140
5.7

This vulnerability in IBM Engineering Requirements Management Doors Next allows authenticated users to spoof email sender identities due to improper s...

Oct 12, 2025
CVE-2025-8074
5.6

This vulnerability in Synology BeeDrive desktop software allows local users to write arbitrary files containing non-sensitive information due to an or...

Dec 4, 2025
CVE-2025-67825
5.5

Nitro PDF Pro for Windows before version 14.42.0.34 displays signer information from unverified PDF fields instead of verified certificate subjects. T...

Jan 8, 2026
CVE-2025-1102
5.5

A CORS misconfiguration vulnerability in Q-Free MaxTime allows attackers to bypass origin validation and perform cross-origin attacks. This affects al...

Feb 12, 2025
CVE-2025-21497
5.5

This vulnerability in MySQL Server's InnoDB component allows authenticated high-privileged attackers to cause denial of service (server crashes/hangs)...

Jan 21, 2025
CVE-2025-12905
5.4

This vulnerability allows a remote attacker to bypass the Mark of the Web security feature in Google Chrome on Windows by tricking users into visiting...

Nov 8, 2025
CVE-2024-21245
5.4

This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows authenticated attackers with low privileges to manipulate business logic via HTTP r...

Jan 21, 2025
CVE-2025-52621
5.3

HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning due to improper validation of the Origin HTTP header. This could allow attacke...

Aug 15, 2025
CVE-2024-6844
5.3

This vulnerability in flask-cors 4.0.1 causes inconsistent CORS policy matching due to improper URL path normalization where '+' characters are conver...

Mar 20, 2025
CVE-2024-56170
5.3

This vulnerability in FORT RPKI validator allows attackers to serve outdated RPKI manifests, causing the system to accept invalid or revoked BGP route...

Dec 18, 2024
CVE-2024-51037
5.3

This vulnerability in kodbox v1.52.04 and earlier allows remote attackers to obtain sensitive information through the captcha feature in the password ...

Nov 15, 2024
CVE-2024-10460
5.3

This vulnerability allows attackers to obscure the origin of external protocol handler prompts using data: URLs within iframes, potentially tricking u...

Oct 29, 2024
CVE-2024-6301
5.3

This vulnerability in Conduit's federation API allows remote servers to impersonate users from any server in most EDU (Education) environments due to ...

Jun 25, 2024
CVE-2023-46715
5.0

This CVE allows authenticated IPSec VPN users with dynamic IP addressing to send spoofed packets appearing to come from other VPN users. It affects Fo...

Jan 14, 2025
CVE-2024-12973
4.7

This CVE describes an origin validation error in Akinsoft OctoCloud that allows HTTP response splitting attacks. Attackers can inject malicious header...

Sep 2, 2025
CVE-2024-5905
4.4

A local privilege bypass vulnerability in Palo Alto Networks Cortex XDR agent on Windows allows low-privileged users to disrupt some agent functionali...

Jun 12, 2024
CVE-2025-37734
4.3

An origin validation error in Kibana's Observability AI Assistant allows attackers to perform Server-Side Request Forgery (SSRF) by forging the Origin...

Nov 12, 2025
CVE-2025-20364
4.3

An unauthenticated attacker on the same wireless network can inject fake Device Analytics action frames into Cisco Wireless Access Points. This could ...

Sep 24, 2025
CVE-2024-45353
4.3

This CVE describes an intent redirection vulnerability in Xiaomi's Quick App framework that allows attackers to redirect app intents to malicious comp...

Mar 27, 2025
CVE-2024-45495
4.3

MSA FieldServer Gateway versions 5.0.0 through 6.5.2 have a cross-origin WebSocket hijacking vulnerability that allows attackers to establish WebSocke...

Nov 29, 2024
CVE-2026-2345
3.6

The Proctorio Chrome Extension vulnerability allows malicious websites to send messages that the extension processes without verifying the sender's or...

Feb 11, 2026
CVE-2025-61740
N/A

This CVE describes an authentication bypass vulnerability in Johnson Controls building automation systems where packet source verification is missing....

Dec 22, 2025

About CWE-346 (CWE-346)

Our database tracks 99 CVEs classified as CWE-346, with 20 rated critical and 48 rated high severity. The average CVSS score for CWE-346 vulnerabilities is 7.5.

External reference: View CWE-346 on MITRE CWE →

Monitor CWE-346 Vulnerabilities

Get alerted when new CWE-346 CVEs affect your infrastructure.

Start Monitoring Free