CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
841 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 12 of 17
- CVE-2022-29220MEDIUMCVSS 6.5EG 6.52022-05-31
github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the…
- CVE-2020-10137MEDIUMCVSS 6.5EG 6.52022-01-10
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with an invalid random …
- CVE-2019-8921MEDIUMCVSS 6.5EG 6.52021-11-29
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes t…
- CVE-2021-34572MEDIUMCVSS 6.5EG 6.52021-09-16
Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.
- CVE-2021-40491MEDIUMCVSS 6.5EG 6.52021-09-03
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
- CVE-2021-21588MEDIUMCVSS 6.5EG 6.52021-07-12
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted acti…
- CVE-2021-23998MEDIUMCVSS 6.5EG 6.52021-06-24
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
- CVE-2021-22339MEDIUMCVSS 6.5EG 6.52021-05-20
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some servic…
- CVE-2020-9230MEDIUMCVSS 6.5EG 6.52020-10-12
WS5800-10 version 10.0.3.25 has a denial of service vulnerability. Due to improper verification of specific message, an attacker may exploit this vulnerability to cause specific function to become abnormal.
- CVE-2019-17228MEDIUMCVSS 6.5EG 6.52020-02-24
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
- CVE-2019-3875MEDIUMCVSS 6.5EG 6.52019-06-12
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or throu…
- CVE-2019-5587MEDIUMCVSS 6.5EG 6.52019-06-04
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.
- CVE-2016-3677MEDIUMCVSS 6.5EG 6.52016-06-13
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
- CVE-2021-27759MEDIUMCVSS 2.3EG 6.52022-05-06
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary …
- CVE-2024-47079MEDIUMCVSS 6.4EG 6.42024-10-07
Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for the broader project. The remote hardware module of the fir…
- CVE-2023-23940MEDIUMCVSS 6.4EG 6.42023-02-03
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signatu…
- CVE-2026-92360MEDIUMCVSS 6.3EG 6.32026-09-16
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START…
- CVE-2026-88819MEDIUMCVSS 6.3EG 6.32026-09-14
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
- CVE-2026-44308MEDIUMCVSS 6.3EG 6.32026-05-14
Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pplications using Spring Cloud AWS SNS HTTP/HTTPS endpoint support (@NotificationMessageMapping, @NotificationSubscriptio…
- CVE-2024-47254MEDIUMCVSS 6.3EG 6.32024-11-05
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain root access to the system.
- CVE-2024-5684MEDIUMCVSS 6.3EG 6.32024-06-06
An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configu…
- CVE-2021-26103MEDIUMCVSS 6.3EG 6.32021-12-08
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may all…
- CVE-2023-32329MEDIUMCVSS 6.2EG 6.22024-02-03
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to…
- CVE-2019-5246MEDIUMCVSS 6.2EG 6.22019-11-13
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verif…
- CVE-2019-5229MEDIUMCVSS 6.2EG 6.22019-11-12
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high…
- CVE-2026-68945MEDIUMCVSS 6.1EG 6.12026-08-03
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing …
- CVE-2026-54266MEDIUMCVSS 6.1EG 6.12026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-…
- CVE-2025-27257MEDIUMCVSS 6.1EG 6.12025-03-10
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated…
- CVE-2020-10751MEDIUMCVSS 6.1EG 6.12020-05-26
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink mess…
- CVE-2026-54586MEDIUMCVSS 6.0EG 6.02026-09-17
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_htt…
- CVE-2026-3446MEDIUMCVSS 6.0EG 6.02026-04-10
When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may …
- CVE-2025-27735MEDIUMCVSS 6.0EG 6.02025-04-08
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- CVE-2022-26579MEDIUMCVSS 6.0EG 6.02022-12-16
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages. The attacker must have shell access to the device and gain root privileges in order to exploit this vulnerabil…
- CVE-2026-105818MEDIUMCVSS 5.9EG 5.92026-10-07
Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate contain…
- CVE-2026-55174MEDIUMCVSS 5.9EG 5.92026-09-30
UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verif…
- CVE-2026-63405MEDIUMCVSS 5.9EG 5.92026-09-18
AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calcul…
- CVE-2026-19941MEDIUMCVSS 5.9EG 5.92026-09-16
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This i…
- CVE-2026-82215MEDIUMCVSS 5.9EG 5.92026-09-11
The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant…
- CVE-2026-20355MEDIUMCVSS 5.9EG 5.92026-09-02
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. Th…
- CVE-2026-15211MEDIUMCVSS 5.9EG 5.92026-08-07
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token an…
- CVE-2026-12901MEDIUMCVSS 5.9EG 5.92026-08-06
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment bei…
- CVE-2026-11361MEDIUMCVSS 5.9EG 5.92026-08-06
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such …
- CVE-2026-13188MEDIUMCVSS 5.9EG 5.92026-07-22
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
- CVE-2026-46538MEDIUMCVSS 5.9EG 5.92026-05-27
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END me…
- CVE-2026-46539MEDIUMCVSS 5.9EG 5.92026-05-21
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the function to return true without perform…
- CVE-2026-6967MEDIUMCVSS 5.9EG 5.92026-04-24
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for del…
- CVE-2026-23656MEDIUMCVSS 5.9EG 5.92026-03-10
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-15598MEDIUMCVSS 5.9EG 5.92026-03-03
A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verif…
- CVE-2026-1642MEDIUMCVSS 5.9EG 5.92026-02-04
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond…
- CVE-2023-46445MEDIUMCVSS 5.9EG 5.92023-11-14
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →