CWE-345
645 CVEs • Abstraction: Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 3Adaptive Security Appliance Adaptive Security Appliance SoftwareFirepower Threat DefenseJun 17, 2026 Apr 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac...Show more |
Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter verification, resulting in user information leakage. |
An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting th...Show more |
Authorized users may install a maliciously modified package file when updating the device via the web user interface. The user may inadvertently use a package file obtained from an unauthorized source or a file that was...Show more |
Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data exce...Show more |
1Cisco 17Ip Phone 6825 Firmware Ip Phone 6841 FirmwareIp Phone 6851 Firmware+14 moreJun 17, 2026 Apr 6, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSR...Show more |
1Trendmicro 2Apex Central Apex OneJun 17, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution. |
Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associated to it. This could allow an attacker to forge a request and bypass the payment system by marking it...Show more |
In multiple functions of odsign_main.cpp, there is a possible way to persist system attack due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User...Show more |
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. |
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code. |
1Schneider Electric 33Scl Series 1029 Ups Firmware Scl Series 1030 Ups FirmwareScl Series 1036 Ups Firmware+30 moreJun 17, 2026 Mar 9, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-U...Show more |
1Custom Content Shortcode Project 1Custom Content Shortcode Jun 17, 2026 Mar 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from t...Show more |
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. |
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute. |
1Amd 10Xilinx Z 7007s Firmware Xilinx Z 7010 FirmwareXilinx Z 7012s Firmware+7 moreJun 17, 2026 Feb 10, 2022 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attac...Show more |
1Dell 214Alienware Area 51m R1 Firmware Alienware Area 51m R2 FirmwareAlienware M15 R3 Firmware+211 moreJun 17, 2026 Feb 9, 2022 N/A· v4 5.1 MEDIUM· v3 3.6 LOW· v2 Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install m...Show more |
1Westerndigital 1My Cloud Os Jun 17, 2026 Jan 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification...Show more |
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection. |
1Silabs 2700 Series Firmware Uzb 7Jun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate or encrypt FIND_NODE_IN_RANGE frames, allowing a remote, unauthenticated attacker to inject a FIND_NODE_IN_RANGE frame with...Show more |