CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 16 of 17
- CVE-2026-32290MEDIUMCVSS 4.7EG 4.72026-03-17
The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash…
- CVE-2024-47255MEDIUMCVSS 4.7EG 4.72024-11-05
In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution with root permissions.
- CVE-2022-22567MEDIUMCVSS 4.7EG 4.72022-02-09
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmwa…
- CVE-2020-3174MEDIUMCVSS 4.7EG 4.72020-02-26
A vulnerability in the anycast gateway feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to learn invalid Address Resolution Protocol (ARP) entries. The ARP entries are for nonlocal IP addr…
- CVE-2019-10157MEDIUMCVSS 4.7EG 4.72019-06-12
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token se…
- CVE-2026-81338MEDIUMCVSS 4.6EG 4.62026-09-23
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts an…
- CVE-2026-35659MEDIUMCVSS 4.6EG 4.62026-04-10
OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could influence CLI routing even when actual service resolution failed. Attackers can exploit unresolved hints to steer routing…
- CVE-2022-28385MEDIUMCVSS 4.6EG 4.62022-06-08
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can manipulate the content of the emulated CD-ROM drive (containing the Windows and macOS client software). The content of …
- CVE-2021-21739MEDIUMCVSS 4.6EG 4.62021-08-05
A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unau…
- CVE-2020-9109MEDIUMCVSS 4.6EG 4.62020-10-12
There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the vic…
- CVE-2026-77955MEDIUMCVSS 4.4EG 4.42026-09-16
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are …
- CVE-2026-41164MEDIUMCVSS 4.4EG 4.42026-05-26
nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by a key present on the node, without vali…
- CVE-2026-25602MEDIUMCVSS 4.4EG 4.42026-05-20
Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the r…
- CVE-2021-26396MEDIUMCVSS 4.4EG 4.42023-01-11
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
- CVE-2021-26368MEDIUMCVSS 4.4EG 4.42022-05-12
Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.
- CVE-2021-41106MEDIUMCVSS 4.4EG 4.42021-09-28
JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of HMAC-based algorithms (HS256, HS384, and HS512) combined with `Lcobucci\JWT\Signer\Key\LocalFileReference` as key are …
- CVE-2019-16000MEDIUMCVSS 4.4EG 4.42020-09-23
A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insuf…
- CVE-2019-1880MEDIUMCVSS 4.4EG 4.42019-06-05
A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to …
- CVE-2018-10626MEDIUMCVSS 4.4EG 4.42018-08-10
Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device informati…
- CVE-2016-3016MEDIUMCVSS 4.4EG 4.42017-02-01
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.
- CVE-2026-108568MEDIUMCVSS 4.3EG 4.32026-10-11
A vulnerability was determined in InstantSoft icms2 up to 2.18.2. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component Billing Module. Executing a manipulation …
- CVE-2026-101278MEDIUMCVSS 4.3EG 4.32026-09-29
A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead…
- CVE-2026-85641MEDIUMCVSS 4.3EG 4.32026-09-16
The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, allo…
- CVE-2026-89050MEDIUMCVSS 4.3EG 4.32026-09-13
The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a pai…
- CVE-2026-79621MEDIUMCVSS 4.3EG 4.32026-09-02
The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated a…
- CVE-2026-78417MEDIUMCVSS 4.3EG 4.32026-08-24
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic…
- CVE-2026-15246MEDIUMCVSS 4.3EG 4.32026-08-06
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user su…
- CVE-2026-12724MEDIUMCVSS 4.3EG 4.32026-07-20
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbi…
- CVE-2026-59930MEDIUMCVSS 4.3EG 4.32026-07-08
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled…
- CVE-2026-44584MEDIUMCVSS 4.3EG 4.32026-06-22
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address…
- CVE-2026-53900MEDIUMCVSS 4.3EG 4.32026-06-16
Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies into requests to an unrelated target domain. This vulnerability…
- CVE-2026-47696MEDIUMCVSS 4.3EG 4.32026-05-29
WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO fo…
- CVE-2023-6323MEDIUMCVSS 4.3EG 4.32024-05-15
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
- CVE-2024-2384MEDIUMCVSS 4.3EG 4.32024-03-20
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This m…
- CVE-2023-3920MEDIUMCVSS 4.3EG 4.32023-09-29
An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a for…
- CVE-2022-36315MEDIUMCVSS 4.3EG 4.32022-12-22
When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.
- CVE-2022-41961MEDIUMCVSS 4.3EG 4.32022-12-16
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they cou…
- CVE-2022-41960MEDIUMCVSS 4.3EG 4.32022-12-16
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` usin…
- CVE-2021-4122MEDIUMCVSS 4.3EG 4.32022-08-24
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user…
- CVE-2021-24825MEDIUMCVSS 4.3EG 4.32022-03-07
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such…
- CVE-2021-29963MEDIUMCVSS 4.3EG 4.32021-06-24
Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.
- CVE-2020-13265MEDIUMCVSS 4.3EG 4.32020-06-19
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
- CVE-2019-15971MEDIUMCVSS 4.3EG 4.32019-11-26
A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to …
- CVE-2018-2434MEDIUMCVSS 4.3EG 4.32018-07-10
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decouple…
- CVE-2017-7674MEDIUMCVSS 4.3EG 4.32017-08-11
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server sid…
- CVE-2014-4883MEDIUMCVSS v2 4.3EG 4.32014-11-28
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct …
- CVE-2026-92138MEDIUMCVSS 4.2EG 4.22026-09-16
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack th…
- CVE-2026-73657MEDIUMCVSS 4.2EG 4.22026-08-13
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.fi…
- CVE-2024-12369MEDIUMCVSS 4.2EG 4.22024-12-09
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen…
- CVE-2017-1773MEDIUMCVSS 4.0EG 4.02018-01-31
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →