In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enable
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the vi
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may g
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is
Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any s
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vu
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature
An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low p
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the addres
An unauthenticated attacker can send a ping request from one network to another through an error in the origin verificat
Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user
Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who c
MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a seve
Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attacke
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitr
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted pr
An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform A
D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.
This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS
@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to version 5.0.0
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijackin
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.
Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process.
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenti
Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.
Incorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attac
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attac
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerabili
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remot
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information a
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and custom
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to webs
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website
A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confus
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to acc
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 812 CVE records associated with CWE-346 in our database. Of these, 61 are critical severity, 221 are high severity, and 397 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started