CWE-345
645 CVEs • Abstraction: Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Umbrella Roaming Client Jun 17, 2026 Sep 23, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerabil...Show more |
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be...Show more |
1Linuxfoundation 1The Update Framework Jun 17, 2026 Sep 9, 2020 N/A· v4 8.2 HIGH· v3 4.9 MEDIUM· v2 Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who...Show more |
1Foxitsoftware 2Phantompdf ReaderJun 17, 2026 Sep 4, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without conce...Show more |
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances. |
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.. |
1Teradici 2Graphics Agent Pcoip Standard AgentJun 17, 2026 Aug 11, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain el...Show more |
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts...Show more |
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble. |
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Jul 9, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability...Show more |
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and do...Show more |
1Cabsoftware 1Reportexpress Proplus Jun 17, 2026 Jun 29, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp). |
1Nvidia 5Geforce Experience Geforce FirmwareNvs Firmware+2 moreJun 17, 2026 Jun 25, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial...Show more |
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow |
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification |
1Mattermost 1Mattermost Server Jun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005. |
1Mids' Reborn Hero Designer Project 1Mids' Reborn Hero Designer Jun 17, 2026 Jun 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attack...Show more |
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote co...Show more |
A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to d...Show more |