CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
662 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 8 of 14
- CVE-2023-4177MEDIUMCVSS 5.7EG 5.72023-08-06
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component Multi-Factor Authentication Code Handler. The manipulation leads to information disclosur…
- CVE-2023-41896CRITICALCVSS 9.0EG 9.02023-10-19
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` param…
- CVE-2023-41898HIGHCVSS 7.8EG 7.82023-10-19
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript ex…
- CVE-2023-42782MEDIUMCVSS 5.3EG 5.32023-10-10
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an…
- CVE-2023-42816MEDIUMCVSS 5.3EG 5.32023-11-13
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was in Kyvernos Notary verifier. An attacker would need control…
- CVE-2023-43636HIGHCVSS 8.8EG 8.82023-09-20
In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured boot” design, the PCR values calculated at different stages of the boot process…
- CVE-2023-43666MEDIUMCVSS 6.5EG 6.52023-10-16
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to upgrade to Apache In…
- CVE-2023-43800HIGHCVSS 7.8EG 7.82023-10-18
Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass t…
- CVE-2023-44402HIGHCVSS 7.0EG 7.02023-12-01
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` fuses enabled. Apps with…
- CVE-2023-45292MEDIUMCVSS 5.3EG 5.32023-12-11
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the funct…
- CVE-2023-45586MEDIUMCVSS 5.0EG 5.02024-05-14
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 thr…
- CVE-2023-4589CRITICALCVSS 7.2EG 9.12023-09-06
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. …
- CVE-2023-46445MEDIUMCVSS 5.9EG 5.92023-11-14
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
- CVE-2023-4699CRITICALCVSS 9.1EG 9.12023-11-06
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-…
- CVE-2023-47630HIGHCVSS 7.1EG 7.12023-11-14
Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control the digest of images used by Kyverno users. The issue would require the attacker to compromise the registry that the Kyve…
- CVE-2023-47631HIGHCVSS 8.8EG 8.82023-11-14
vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not check if an image is allowed to run if a `parent_id` is set. A…
- CVE-2023-48238HIGHCVSS 7.5EG 7.52023-11-17
joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Versions prior to 4.0.0 are vulnerable to a J…
- CVE-2023-49087HIGHCVSS 7.5EG 7.52023-11-30
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptogra…
- CVE-2023-51655CRITICALCVSS 9.8EG 9.82023-12-21
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
- CVE-2023-51764MEDIUMCVSS 5.3EG 5.32023-12-24
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use…
- CVE-2023-51765MEDIUMCVSS 5.3EG 5.32023-12-24
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism…
- CVE-2023-51766MEDIUMCVSS 5.3EG 5.32023-12-24
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF prote…
- CVE-2023-52109HIGHCVSS 7.5EG 7.52024-01-16
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-52546HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-5366HIGHCVSS 5.5EG 7.12023-10-06
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed targ…
- CVE-2023-5450HIGHCVSS 7.8EG 7.82023-10-10
An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process. Note: Software versions which have reached End of Te…
- CVE-2023-5482HIGHCVSS 8.8EG 8.82023-11-01
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-5548MEDIUMCVSS 5.3EG 5.32023-11-09
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
- CVE-2023-5747HIGHCVSS 8.8EG 8.82023-11-13
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing …
- CVE-2023-6236HIGHCVSS 7.3EG 7.32024-04-10
A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to access the second tenant, it should prompt the user to log in again since the second tenant is secured with a differen…
- CVE-2023-6323MEDIUMCVSS 4.3EG 4.32024-05-15
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
- CVE-2023-6533MEDIUMCVSS 6.5EG 6.52024-02-21
Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller.…
- CVE-2024-10237HIGHCVSS 7.2EG 7.22025-02-04
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process
- CVE-2024-10977LOWCVSS 3.1EG 3.12024-11-14
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error …
- CVE-2024-11666CRITICALCVSS 9.0EG 9.02024-11-24
Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since peer verification is disabled everywhere. Therefore, remote unauthent…
- CVE-2024-12369MEDIUMCVSS 4.2EG 4.22024-12-09
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen…
- CVE-2024-1321MEDIUMCVSS 5.3EG 5.32024-03-13
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of ord…
- CVE-2024-1554CRITICALCVSS 9.8EG 9.82024-02-20
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser c…
- CVE-2024-1718MEDIUMCVSS 5.3EG 5.32024-06-04
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and includin…
- CVE-2024-23601CRITICALCVSS 9.8EG 9.82024-05-28
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this v…
- CVE-2024-2382MEDIUMCVSS 5.3EG 5.32024-06-04
The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates…
- CVE-2024-2384MEDIUMCVSS 4.3EG 4.32024-03-20
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This m…
- CVE-2024-23922MEDIUMCVSS 6.8EG 6.82024-09-23
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authenticat…
- CVE-2024-24557MEDIUMCVSS 6.9EG 6.92024-02-01
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being…
- CVE-2024-25584MEDIUMCVSS 5.3EG 5.32024-09-06
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will sp…
- CVE-2024-25638HIGHCVSS 8.9EG 8.92024-07-22
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
- CVE-2024-27244MEDIUMCVSS 6.7EG 6.72024-05-15
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2024-27305MEDIUMCVSS 5.3EG 5.32024-03-12
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol.…
- CVE-2024-27773HIGHCVSS 8.8EG 8.82024-03-18
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE
- CVE-2024-28251MEDIUMCVSS 5.6EG 5.62024-03-14
Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading…
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →