Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Acces
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the ori
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13,
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thund
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints.
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the en
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest u
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak Keyc
Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140
An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP se
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe
Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline Hub dashboard
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Nav
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sig
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configu
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted fro
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy
MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validat
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.
OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin va
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glance
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compr
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 333 CVE records associated with CWE-346 in our database. Of these, 23 are critical severity, 87 are high severity, and 187 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started