CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
841 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 8 of 17
- CVE-2026-25474HIGHCVSS 7.5EG 7.52026-02-19
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header…
- CVE-2026-1195HIGHCVSS 7.5EG 7.52026-01-20
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible …
- CVE-2025-59420HIGHCVSS 7.5EG 7.52025-09-22
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand�…
- CVE-2025-30192HIGHCVSS 7.5EG 7.52025-07-21
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by…
- CVE-2025-53548HIGHCVSS 7.5EG 7.52025-07-09
Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
- CVE-2025-29842HIGHCVSS 7.5EG 7.52025-05-13
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2024-47867HIGHCVSS 7.5EG 7.52024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious code. If an attacker g…
- CVE-2023-28457HIGHCVSS 7.5EG 7.52024-09-18
An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.
- CVE-2024-38198HIGHCVSS 7.5EG 7.52024-08-13
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2024-37968HIGHCVSS 7.5EG 7.52024-08-13
Windows DNS Spoofing Vulnerability
- CVE-2024-39689HIGHCVSS 7.5EG 7.52024-07-05
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `G…
- CVE-2024-37370HIGHCVSS 7.5EG 7.52024-06-28
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
- CVE-2024-33687HIGHCVSS 7.5EG 7.52024-06-24
Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.
- CVE-2023-52546HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-30250HIGHCVSS 7.5EG 7.52024-04-04
Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques. Versions from 1.2.0 to 1.3.1 of Astro-Shield allow bypass to the allow-lists for cross-ori…
- CVE-2023-52109HIGHCVSS 7.5EG 7.52024-01-16
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-49087HIGHCVSS 7.5EG 7.52023-11-30
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptogra…
- CVE-2023-48238HIGHCVSS 7.5EG 7.52023-11-17
joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Versions prior to 4.0.0 are vulnerable to a J…
- CVE-2023-38552HIGHCVSS 7.5EG 7.52023-10-18
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the int…
- CVE-2023-26141HIGHCVSS 7.5EG 7.52023-09-14
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will…
- CVE-2023-37920HIGHCVSS 7.5EG 7.52023-07-25
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's ro…
- CVE-2023-23941HIGHCVSS 7.5EG 7.52023-02-03
SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be id…
- CVE-2022-38873HIGHCVSS 7.5EG 7.52022-12-20
D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31…
- CVE-2022-36360HIGHCVSS 7.5EG 7.52022-10-11
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verifi…
- CVE-2022-2255HIGHCVSS 7.5EG 7.52022-08-25
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is m…
- CVE-2022-37008HIGHCVSS 7.5EG 7.52022-08-10
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
- CVE-2022-28370HIGHCVSS 7.5EG 7.52022-07-14
On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmware update for the device. /lib/functions/wnc_jsonsh/wnc_crtc_fw.sh has no cryptographic validation o…
- CVE-2015-5236HIGHCVSS 7.5EG 7.52022-07-07
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin,…
- CVE-2022-20795HIGHCVSS 7.5EG 7.52022-04-21
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high C…
- CVE-2020-14116HIGHCVSS 7.5EG 7.52022-04-21
An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this.
- CVE-2021-4031HIGHCVSS 7.5EG 7.52022-03-18
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking items as payed withou…
- CVE-2021-46559HIGHCVSS 7.5EG 7.52022-01-26
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.
- CVE-2020-19769HIGHCVSS 7.5EG 7.52021-09-07
A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from victim users via a crafted script.
- CVE-2020-19768HIGHCVSS 7.5EG 7.52021-09-07
A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from victim users via a crafted script.
- CVE-2021-31228HIGHCVSS 7.5EG 7.52021-08-19
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's r…
- CVE-2021-33840HIGHCVSS 7.5EG 7.52021-06-04
The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.
- CVE-2021-31783HIGHCVSS 7.5EG 7.52021-04-26
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
- CVE-2020-25019HIGHCVSS 7.5EG 7.52020-08-29
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
- CVE-2020-15899HIGHCVSS 7.5EG 7.52020-07-28
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
- CVE-2020-13272HIGHCVSS 7.5EG 7.52020-06-19
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
- CVE-2020-14453HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
- CVE-2020-10831HIGHCVSS 7.5EG 7.52020-03-24
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can trigger an update to arbitrary touch-screen firmware. The Samsung ID is SVE-2019-16013 (March 2020).
- CVE-2019-8112HIGHCVSS 7.5EG 7.52019-11-05
A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can bypass the email confirmation mechanism via GET request that captures relevant account data obtained…
- CVE-2019-3979HIGHCVSS 7.5EG 7.52019-10-29
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a rem…
- CVE-2019-10943HIGHCVSS 7.5EG 7.52019-08-13
A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS var…
- CVE-2019-7323HIGHCVSS 7.5EG 7.52019-02-04
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update process relies on …
- CVE-2018-6562HIGHCVSS 7.5EG 7.52018-05-18
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.
- CVE-2017-14091HIGHCVSS 7.5EG 7.52017-12-16
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange …
- CVE-2017-10624HIGHCVSS 7.5EG 7.52017-10-13
Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos S…
- CVE-2017-12972HIGHCVSS 7.5EG 7.52017-08-20
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so th…
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →