Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that a
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web
An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. The aff
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow frami
Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS reques
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to imperson
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to exploit a security feature bypass due to Microsoft Edg
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 812 CVE records associated with CWE-346 in our database. Of these, 61 are critical severity, 221 are high severity, and 397 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started