Vulnerabilities > Origin Validation Error

DATE CVE VULNERABILITY TITLE RISK
2022-09-19 CVE-2022-40140 Origin Validation Error vulnerability in Trendmicro Apex ONE 2019
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations.
local
low complexity
trendmicro CWE-346
5.5
2022-08-17 CVE-2022-23764 Origin Validation Error vulnerability in Teruten Webcube 1.0.5.5
The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update.
network
low complexity
teruten CWE-346
critical
9.8
2022-07-26 CVE-2022-1497 Origin Validation Error vulnerability in Google Chrome
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
network
low complexity
google CWE-346
6.5
2022-07-20 CVE-2022-26137 Origin Validation Error vulnerability in Atlassian products
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses.
network
low complexity
atlassian CWE-346
8.8
2022-06-28 CVE-2022-23763 Origin Validation Error vulnerability in Douzone Neors
Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files.
network
low complexity
douzone CWE-346
8.8
2022-06-14 CVE-2022-30228 Origin Validation Error vulnerability in Siemens Sicam Gridedge Essential
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6), SICAM GridEdge Essential Intel (All versions < V2.6.6), SICAM GridEdge Essential with GDS ARM (All versions < V2.6.6), SICAM GridEdge Essential with GDS Intel (All versions < V2.6.6).
network
low complexity
siemens CWE-346
6.5
2022-05-20 CVE-2022-25227 Origin Validation Error vulnerability in Cybelesoft Thinfinity VNC 4.0.0.1
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.
network
low complexity
cybelesoft CWE-346
8.8
2022-04-28 CVE-2022-29818 Origin Validation Error vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
local
low complexity
jetbrains CWE-346
7.1
2022-04-04 CVE-2021-32985 Origin Validation Error vulnerability in Aveva System Platform 2017/2020
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.
network
low complexity
aveva CWE-346
7.2
2022-03-21 CVE-2020-24772 Origin Validation Error vulnerability in Clash Project Clash 0.11.4
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share.
network
low complexity
clash-project CWE-346
8.8