Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise
Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fi
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem
Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-
Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner
The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access func
locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of a
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set wit
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke
Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t
Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to
Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Ve
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 11
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions th
CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite pr
Frequently Asked Questions
What is CWE-346?
CWE-346 (CWE-346) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-346?
There are 435 CVE records associated with CWE-346 in our database. Of these, 32 are critical severity, 114 are high severity, and 233 are medium severity.
How can I protect against CWE-346 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-346 using AI-powered security agents.
Detect CWE-346 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-346 vulnerabilities across your infrastructure.
Get Started