CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
663 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 9 of 14
- CVE-2024-30162HIGHCVSS 7.2EG 7.22024-06-07
Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted…
- CVE-2024-30250HIGHCVSS 7.5EG 7.52024-04-04
Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques. Versions from 1.2.0 to 1.3.1 of Astro-Shield allow bypass to the allow-lists for cross-ori…
- CVE-2024-3049HIGHCVSS 5.9EG 7.42024-06-06
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
- CVE-2024-31341MEDIUMCVSS 5.3EG 5.32024-05-17
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.
- CVE-2024-3173HIGHCVSS 8.8EG 8.82024-07-16
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
- CVE-2024-33494MEDIUMCVSS 6.5EG 6.52024-05-14
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All ver…
- CVE-2024-33687HIGHCVSS 7.5EG 7.52024-06-24
Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.
- CVE-2024-34354MEDIUMCVSS 6.5EG 6.52024-05-14
CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not …
- CVE-2024-35175MEDIUMCVSS 5.3EG 5.32024-05-14
sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059…
- CVE-2024-37370HIGHCVSS 7.5EG 7.52024-06-28
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
- CVE-2024-37968HIGHCVSS 7.5EG 7.52024-08-13
Windows DNS Spoofing Vulnerability
- CVE-2024-38198HIGHCVSS 7.5EG 7.52024-08-13
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2024-38432MEDIUMCVSS 5.5EG 5.52024-07-30
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
- CVE-2024-39689HIGHCVSS 7.5EG 7.52024-07-05
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `G…
- CVE-2024-39805HIGHCVSS 7.8EG 7.82025-02-12
Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-40644MEDIUMCVSS 6.8EG 6.82024-07-18
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user a…
- CVE-2024-42483MEDIUMCVSS 6.5EG 6.52024-09-12
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared…
- CVE-2024-43108MEDIUMCVSS 5.3EG 5.32024-09-26
The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is advised to con…
- CVE-2024-43428HIGHCVSS 7.7EG 7.72024-11-07
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
- CVE-2024-45410CRITICALCVSS 9.8EG 9.82024-09-19
Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a…
- CVE-2024-47079MEDIUMCVSS 6.4EG 6.42024-10-07
Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for the broader project. The remote hardware module of the fir…
- CVE-2024-47123MEDIUMCVSS 5.3EG 5.32024-09-26
The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is recommended to continu…
- CVE-2024-47254MEDIUMCVSS 6.3EG 6.32024-11-05
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain root access to the system.
- CVE-2024-47255MEDIUMCVSS 4.7EG 4.72024-11-05
In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution with root permissions.
- CVE-2024-47867HIGHCVSS 7.5EG 7.52024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious code. If an attacker g…
- CVE-2024-48916HIGHCVSS 8.1EG 8.12025-07-30
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in t…
- CVE-2024-52548MEDIUMCVSS 6.7EG 6.72024-12-03
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
- CVE-2024-53259MEDIUMCVSS 6.5EG 6.52024-12-02
quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet. Since affected quic-go versions used IP_PMTUDISC_DO, the kernel would then return a "message too large" error on send…
- CVE-2024-54111MEDIUMCVSS 5.7EG 5.72024-12-12
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-5458MEDIUMCVSS 5.3EG 5.32024-06-09
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result…
- CVE-2024-55929MEDIUMCVSS 5.3EG 5.32025-01-23
A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as though messages are sent from trusted sources.
- CVE-2024-5684MEDIUMCVSS 6.3EG 6.32024-06-06
An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configu…
- CVE-2024-58267HIGHCVSS 8.0EG 8.02025-10-02
A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Ran…
- CVE-2024-7256HIGHCVSS 8.8EG 8.82024-08-01
Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-7847HIGHCVSS 7.7EG 7.72024-10-14
VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A …
- CVE-2024-7979HIGHCVSS 7.8EG 7.82024-08-21
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)
- CVE-2024-7980HIGHCVSS 7.8EG 7.82024-08-21
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)
- CVE-2024-8356HIGHCVSS 7.8EG 8.82024-11-22
Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Visteon Infotainment sys…
- CVE-2025-0092MEDIUMCVSS 6.5EG 6.52025-08-26
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges need…
- CVE-2025-0149MEDIUMCVSS 6.5EG 6.52025-03-11
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
- CVE-2025-0510MEDIUMCVSS 6.5EG 6.52025-02-04
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability was fixed in Thunderbird 128.7 and Thunderbird 135.
- CVE-2025-1108HIGHCVSS 8.6EG 8.62025-02-07
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must …
- CVE-2025-11195LOWCVSS 3.3EG 3.32025-09-30
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack…
- CVE-2025-12080MEDIUMCVSS 6.9EG 6.92025-10-27
On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes is incorrectly impl…
- CVE-2025-12245MEDIUMCVSS 5.3EG 5.32025-10-27
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl l…
- CVE-2025-12295MEDIUMCVSS 6.6EG 6.62025-10-27
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can lead to improper verification of cryptographic signature. The …
- CVE-2025-12752MEDIUMCVSS 5.3EG 5.32025-11-22
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This m…
- CVE-2025-14444MEDIUMCVSS 5.3EG 5.32026-02-18
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' …
- CVE-2025-15154MEDIUMCVSS 5.3EG 5.32025-12-28
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For le…
- CVE-2025-15385CRITICALCVSS 9.8EG 9.82026-01-06
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →