CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
841 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 13 of 17
- CVE-2021-22947MEDIUMCVSS 5.9EG 5.92021-09-29
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to T…
- CVE-2021-38597MEDIUMCVSS 5.9EG 5.92021-08-12
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.
- CVE-2019-5291MEDIUMCVSS 5.9EG 5.92019-12-13
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the p…
- CVE-2017-12740MEDIUMCVSS 5.9EG 5.92017-12-26
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while perfor…
- CVE-2016-1731MEDIUMCVSS 5.9EG 5.92016-03-14
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
- CVE-2016-0818MEDIUMCVSS 5.9EG 5.92016-03-12
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trust…
- CVE-2026-54764MEDIUMCVSS 5.8EG 5.82026-07-06
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authenticati…
- CVE-2022-39199MEDIUMCVSS 5.8EG 5.82022-11-22
immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to distinguish between different server instance so that the client can connect to different immudb instances and keep the state …
- CVE-2026-102711MEDIUMCVSS 5.7EG 5.72026-09-29
Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image…
- CVE-2025-31356MEDIUMCVSS 5.7EG 5.72026-08-11
Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with …
- CVE-2026-42206MEDIUMCVSS 5.7EG 5.72026-05-08
Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerator::generate() and includes it in the aut…
- CVE-2025-25188MEDIUMCVSS 5.7EG 5.72025-02-10
Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DNSSEC verification in the client library,…
- CVE-2024-54111MEDIUMCVSS 5.7EG 5.72024-12-12
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-4177MEDIUMCVSS 5.7EG 5.72023-08-06
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component Multi-Factor Authentication Code Handler. The manipulation leads to information disclosur…
- CVE-2019-19160MEDIUMCVSS 5.7EG 5.72020-06-29
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
- CVE-2026-55663MEDIUMCVSS 5.6EG 5.62026-08-25
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msw…
- CVE-2025-2346MEDIUMCVSS 5.6EG 5.62025-03-16
A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain Handler. The manipulation of the argument Domain Name leads t…
- CVE-2024-28251MEDIUMCVSS 5.6EG 5.62024-03-14
Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading…
- CVE-2021-41087MEDIUMCVSS 5.6EG 5.62021-09-21
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a layout) are able to …
- CVE-2026-74890MEDIUMCVSS 5.5EG 5.52026-08-17
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code executi…
- CVE-2026-50526MEDIUMCVSS 5.5EG 5.52026-07-14
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
- CVE-2026-45792MEDIUMCVSS 5.5EG 5.52026-05-20
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directo…
- CVE-2026-22703MEDIUMCVSS 5.5EG 5.52026-01-10
Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact'…
- CVE-2024-38432MEDIUMCVSS 5.5EG 5.52024-07-30
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
- CVE-2022-44420MEDIUMCVSS 5.5EG 5.52023-05-09
In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges.
- CVE-2022-46692MEDIUMCVSS 5.5EG 5.52022-12-15
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing malicio…
- CVE-2022-20396MEDIUMCVSS 5.5EG 5.52022-09-13
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execut…
- CVE-2020-14122MEDIUMCVSS 5.5EG 5.52022-04-21
Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage.
- CVE-2020-23906MEDIUMCVSS 5.5EG 5.52021-11-10
FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insufficient verification of data authenticity.
- CVE-2021-22460MEDIUMCVSS 5.5EG 5.52021-10-28
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to bypass the control mechanism.
- CVE-2021-22419MEDIUMCVSS 5.5EG 5.52021-08-03
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exploit this vulnerability to cause persistent dos.
- CVE-2021-28678MEDIUMCVSS 5.5EG 5.52021-06-02
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times o…
- CVE-2020-9885MEDIUMCVSS 5.5EG 5.52020-10-16
An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an…
- CVE-2019-5478MEDIUMCVSS 5.5EG 5.52019-09-03
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior.
- CVE-2019-12804MEDIUMCVSS 5.5EG 5.52019-07-10
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.
- CVE-2022-2789MEDIUMCVSS 4.7EG 5.52022-08-19
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.
- CVE-2026-13720MEDIUMCVSS 5.4EG 5.42026-09-30
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authori…
- CVE-2026-82813MEDIUMCVSS 5.4EG 5.42026-08-31
A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient ve…
- CVE-2026-82811MEDIUMCVSS 5.4EG 5.42026-08-31
A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the…
- CVE-2026-71858MEDIUMCVSS 5.4EG 5.42026-08-17
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal Ope…
- CVE-2026-53862MEDIUMCVSS 5.4EG 5.42026-06-16
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing a…
- CVE-2026-31835MEDIUMCVSS 5.4EG 5.42026-05-05
Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags…
- CVE-2023-26467MEDIUMCVSS 5.4EG 5.42023-04-10
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
- CVE-2022-36111MEDIUMCVSS 5.4EG 5.42022-11-23
immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing …
- CVE-2022-31598MEDIUMCVSS 5.4EG 5.42022-07-12
Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information c…
- CVE-2019-5431MEDIUMCVSS 5.4EG 5.42019-05-06
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate cr…
- CVE-2018-10894MEDIUMCVSS 5.4EG 5.42018-08-01
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
- CVE-2026-107420MEDIUMCVSS 5.3EG 5.32026-10-10
Unauthenticated Bypass Vulnerability in Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway <= 1.7.2 versions.
- CVE-2026-103517MEDIUMCVSS 5.3EG 5.32026-10-08
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attac…
- CVE-2026-105161MEDIUMCVSS 5.3EG 5.32026-10-04
A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The at…
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →