CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 15 of 17
- CVE-2022-4533MEDIUMCVSS 5.3EG 5.32024-09-19
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request lo…
- CVE-2024-25584MEDIUMCVSS 5.3EG 5.32024-09-06
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will sp…
- CVE-2022-4539MEDIUMCVSS 5.3EG 5.32024-08-31
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request log…
- CVE-2024-5458MEDIUMCVSS 5.3EG 5.32024-06-09
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result…
- CVE-2024-2382MEDIUMCVSS 5.3EG 5.32024-06-04
The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates…
- CVE-2024-1718MEDIUMCVSS 5.3EG 5.32024-06-04
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and includin…
- CVE-2024-31341MEDIUMCVSS 5.3EG 5.32024-05-17
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.
- CVE-2024-35175MEDIUMCVSS 5.3EG 5.32024-05-14
sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059…
- CVE-2023-35764MEDIUMCVSS 5.3EG 5.32024-04-03
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
- CVE-2024-1321MEDIUMCVSS 5.3EG 5.32024-03-13
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of ord…
- CVE-2024-27305MEDIUMCVSS 5.3EG 5.32024-03-12
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol.…
- CVE-2023-51766MEDIUMCVSS 5.3EG 5.32023-12-24
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF prote…
- CVE-2023-51765MEDIUMCVSS 5.3EG 5.32023-12-24
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism…
- CVE-2023-51764MEDIUMCVSS 5.3EG 5.32023-12-24
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use…
- CVE-2023-45292MEDIUMCVSS 5.3EG 5.32023-12-11
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the funct…
- CVE-2023-42816MEDIUMCVSS 5.3EG 5.32023-11-13
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was in Kyvernos Notary verifier. An attacker would need control…
- CVE-2023-5548MEDIUMCVSS 5.3EG 5.32023-11-09
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
- CVE-2023-42782MEDIUMCVSS 5.3EG 5.32023-10-10
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an…
- CVE-2023-35906MEDIUMCVSS 5.3EG 5.32023-09-05
IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.
- CVE-2023-41045MEDIUMCVSS 5.3EG 5.32023-08-31
Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket for outgoing DNS queries and while that socket is bound to a random port number it is never…
- CVE-2020-1755MEDIUMCVSS 5.3EG 5.32022-08-16
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
- CVE-2020-11985MEDIUMCVSS 5.3EG 5.32020-08-07
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue w…
- CVE-2020-15699MEDIUMCVSS 5.3EG 5.32020-07-15
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
- CVE-2020-12063MEDIUMCVSS 5.3EG 5.32020-04-24
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character. This is potentially relevant when the …
- CVE-2020-8660MEDIUMCVSS 5.3EG 5.32020-03-04
CNCF Envoy through 1.13.0 TLS inspector bypass. TLS inspector could have been bypassed (not recognized as a TLS client) by a client using only TLS 1.3. Because TLS extensions (SNI, ALPN) were not inspected, those connections might have bee…
- CVE-2019-0379MEDIUMCVSS 5.3EG 5.32019-10-08
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check
- CVE-2019-15162MEDIUMCVSS 5.3EG 5.32019-10-03
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
- CVE-2019-11737MEDIUMCVSS 5.3EG 5.32019-09-27
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content. This vulnerability a…
- CVE-2019-12620MEDIUMCVSS 5.3EG 5.32019-09-18
A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for …
- CVE-2018-17938MEDIUMCVSS 5.3EG 5.32018-10-03
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
- CVE-2017-10862MEDIUMCVSS 5.3EG 5.32017-10-12
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
- CVE-2015-9232MEDIUMCVSS 5.3EG 5.32017-09-20
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation…
- CVE-2025-24882MEDIUMCVSS 5.2EG 5.22025-01-29
regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
- CVE-2023-30559MEDIUMCVSS 5.2EG 5.22023-07-13
The firmware update package for the wireless card is not properly signed and can be modified.
- CVE-2022-33861MEDIUMCVSS 5.1EG 5.12024-11-25
IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.
- CVE-2026-13513MEDIUMCVSS 5.0EG 5.02026-06-28
A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulation results in insufficient verification o…
- CVE-2026-13507MEDIUMCVSS 5.0EG 5.02026-06-28
A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manip…
- CVE-2023-45586MEDIUMCVSS 5.0EG 5.02024-05-14
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 thr…
- CVE-2014-0364MEDIUMCVSS v2 5.0EG 5.02014-04-30
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.
- CVE-2026-102140MEDIUMCVSS 4.9EG 4.92026-09-30
An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or f…
- CVE-2026-45057MEDIUMCVSS 4.9EG 4.92026-06-04
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is …
- CVE-2018-17287MEDIUMCVSS 4.9EG 4.92019-04-18
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by a…
- CVE-2017-1405MEDIUMCVSS 4.4EG 4.92018-06-08
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392.
- CVE-2026-104419MEDIUMCVSS 4.8EG 4.82026-10-02
Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the …
- CVE-2026-10724MEDIUMCVSS 4.8EG 4.82026-07-20
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortco…
- CVE-2026-48783MEDIUMCVSS 4.8EG 4.82026-06-17
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's clai…
- CVE-2023-32993MEDIUMCVSS 4.8EG 4.82023-05-16
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to interce…
- CVE-2022-46422MEDIUMCVSS 4.8EG 4.82022-12-20
An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.
- CVE-2019-18905MEDIUMCVSS 4.8EG 4.82020-04-03
A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyas…
- CVE-2026-32294MEDIUMCVSS 4.7EG 4.72026-03-17
JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →