CWE-345
645 CVEs • Abstraction: Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apsystems 1Alternergy Power Control Software Jun 17, 2026 May 11, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php. |
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is b...Show more |
In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges. |
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity. |
1Blackvue 2Dr750 2ch Ir Lte Firmware Dr750 2ch Lte FirmwareJun 17, 2026 Apr 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution. |
A man in the middle can redirect traffic to a malicious server in a compromised configuration. |
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation. |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an atta...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific cra...Show more |
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to upload a file to the device by changing the extension of a malicious file to an accepted file type. |
A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinSpend of the file CoinSpend.cpp of the component Proof Handler. The manipulation leads to insufficien...Show more |
authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user....Show more |
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected file...Show more |
SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to P...Show more |
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling...Show more |
1Snapav 1Wattbox Wb 300 Ip 3 Firmware Jun 17, 2026 Jan 30, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device an...Show more |
Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification. |
1Amd 41Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7232p Firmware+38 moreJun 17, 2026 Jan 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.
|
1Amd 24Epyc 7003 Firmware Epyc 72f3 FirmwareEpyc 7313 Firmware+21 moreJun 17, 2026 Jan 11, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
|