An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series al
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions startin
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected is the function messageR
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macO
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive i
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause a persistent denial of service by manipu
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service b
An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Monterey 12.
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventu
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5
In notification access permission dialog box, malicious application can embedded a very long service label that overflow
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic informa
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory o
An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticate
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from anot
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) remo
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOr
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Ex
Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipu
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to o
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross
The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessa
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscat
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate secur
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to ob
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perfor
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zs
The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepowe
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the
A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemo
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged re
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected software does not
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fil
The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote a
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, wat
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website c
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirec
A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and
Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 812 CVE records associated with CWE-346 in our database. Of these, 61 are critical severity, 221 are high severity, and 397 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started