An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authori
PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communicatio
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 ve
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cros
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrect
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-ori
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentiall
sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that u
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 an
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the con
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker
In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system
The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 doe
The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting System
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both,
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incompl
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surpris
Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attac
glFusion CMS v1.7.9 is affected by an arbitrary user impersonation vulnerability in /public_html/comment.php. The attack
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside th
DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextF
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server h
In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.
Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker t
Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to l
Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to
Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a c
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-o
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to le
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perfor
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another o
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while r
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 812 CVE records associated with CWE-346 in our database. Of these, 61 are critical severity, 221 are high severity, and 397 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started