The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validati
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the b
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indo
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host na
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_managemen
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an atta
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pag
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the prod
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), n
A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacke
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had com
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location propert
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass cont
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoo
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected c
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, w
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, w
The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, whic
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a vic
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers corr
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers corr
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitm
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com t
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal imag
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to re
In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could le
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP r
The Auto-Maskin products utilize an undocumented custom protocol to set up Modbus communications with other devices with
The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'a
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin o
Response header name interning does not have same-origin protections and these headers are stored in a global registry.
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th
EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote a
An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmwa
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creat
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 812 CVE records associated with CWE-346 in our database. Of these, 61 are critical severity, 221 are high severity, and 397 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started