Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2025-03-16 CVE-2025-2346 A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic.
network
high complexity
CWE-346
5.6
2025-03-03 CVE-2025-25302 Origin Validation Error vulnerability in Danielgatis Rembg
Rembg is a tool to remove images background.
network
low complexity
danielgatis CWE-346
6.5
2025-01-14 CVE-2023-46715 Origin Validation Error vulnerability in Fortinet Fortios
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.
network
low complexity
fortinet CWE-346
4.3
2024-12-12 CVE-2024-44212 Origin Validation Error vulnerability in Apple products
A cookie management issue was addressed with improved state management.
network
low complexity
apple CWE-346
5.3
2024-10-29 CVE-2024-6674 Origin Validation Error vulnerability in Lollms web UI
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services.
network
low complexity
lollms CWE-346
7.1
2024-09-17 CVE-2024-44187 Origin Validation Error vulnerability in Apple products
A cross-origin issue existed with "iframe" elements.
network
low complexity
apple CWE-346
6.5
2024-08-12 CVE-2024-41475 Origin Validation Error vulnerability in SIR Gnuboard 6.0.7
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
network
low complexity
sir CWE-346
8.8
2024-08-06 CVE-2024-23458 Origin Validation Error vulnerability in Zscaler Client Connector
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation.
local
low complexity
zscaler CWE-346
7.8
2024-08-01 CVE-2024-41926 Origin Validation Error vulnerability in Mattermost Server
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
network
low complexity
mattermost CWE-346
4.3
2024-07-29 CVE-2024-41143 Origin Validation Error vulnerability in Skygroup Skysea Client View
Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e.
local
low complexity
skygroup CWE-346
7.8