← Back
CWE-345

645 CVEs • Abstraction: Class

Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

JSON object

Loading...

CVEs (645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Umbrella Roaming Client
Jun 17, 2026
Sep 23, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerabil...Show more
A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device. The vulnerability is due to insufficient verification of the Windows Installer. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows file system. A successful exploit could allow the attacker to bypass configured policy and install unapproved applications.Show less
1Titanhq
1Spamtitan
Jun 17, 2026
Sep 17, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be...Show more
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.Show less
1Linuxfoundation
1The Update Framework
Jun 17, 2026
Sep 9, 2020
N/A· v4
8.2 HIGH· v3
4.9 MEDIUM· v2
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who...Show more
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack) culminating in a version which has not been correctly signed to control the trust chain for future updates. This is fixed in version 0.12 and newer.Show less
1Foxitsoftware
2Phantompdf
Reader
Jun 17, 2026
Sep 4, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without conce...Show more
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.Show less
1Jitsi
1Meet Electron
Jun 17, 2026
Aug 29, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
1Hashicorp
1Vault
Jun 17, 2026
Aug 26, 2020
N/A· v4
8.2 HIGH· v3
7.5 HIGH· v2
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
1Teradici
2Graphics Agent
Pcoip Standard Agent
Jun 17, 2026
Aug 11, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain el...Show more
A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain elevated privileges via execution in the context of the PCoIP Agent process.Show less
1Apache
1Http Server
Jun 17, 2026
Aug 7, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts...Show more
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.Show less
1Grin
1Grin
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
1Joomla
1Joomla
Jun 17, 2026
Jul 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
Jul 9, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability...Show more
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.Show less
1Ledger
1Ledger Live
Jun 17, 2026
Jul 2, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and do...Show more
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and does not decrease the balance when it is canceled. As a result, users are exposed to basic double spending attacks, amplified double spending attacks, and DoS attacks without user consent.Show less
1Cabsoftware
1Reportexpress Proplus
Jun 17, 2026
Jun 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
1Nvidia
5Geforce Experience
Geforce FirmwareNvs Firmware+2 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial...Show more
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
1Mattermost
1Mattermost Server
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 5.21.0. Socket read operations are not appropriately restricted, which allows attackers to cause a denial of service, aka MMSA-2020-0005.
1Mids' Reborn Hero Designer Project
1Mids' Reborn Hero Designer
Jun 17, 2026
Jun 11, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attack...Show more
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a man-in-the-middle attack against this connection and replace executable files with malicious versions, which the operating system then executes under the context of the user running Hero Designer.Show less
1Wago
1Pfc200 Firmware
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote co...Show more
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.8 MEDIUM· v3
7.1 HIGH· v2
A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to d...Show more
A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions to an affected device. The vulnerability is due to insufficient verification of authenticity of received Encapsulating Security Payload (ESP) packets. An attacker could exploit this vulnerability by tampering with ESP cleartext values as a man-in-the-middle.Show less