CWE-345
645 CVEs • Abstraction: Class
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CVEs (645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 41Zu11eg Firmware Zu15eg FirmwareZu17eg Firmware+38 moreJun 17, 2026 Sep 3, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure boot behavior. |
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods. |
1Siemens 12Simatic Et 200sp Open Controller Cpu 1515sp Pc2 Firmware Simatic Et 200sp Open Controller Cpu 1515sp Pc FirmwareSimatic S7 1200 Cpu 1211c Firmware+9 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC...Show more |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapJun 17, 2026 Jul 31, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a tr...Show more |
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms. |
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update. |
1Cisco 1Advanced Malware Protection For Endpoints Jun 17, 2026 Jul 6, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insuf...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Jun 12, 2019 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate it...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Jun 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a mal...Show more |
1Cisco 1Unified Computing System Server Firmware Jun 17, 2026 Jun 5, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulne...Show more |
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through...Show more |
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to p...Show more |
1Cloudfoundry 1Bosh Backup And Restore Jun 17, 2026 Apr 24, 2019 N/A· v4 7.1 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and R...Show more |
5Canonical FedoraprojectFreeradius+2 more10Enterprise Linux Enterprise Linux EusEnterprise Linux Server+7 moreJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dr...Show more |
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, a...Show more |
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019...Show more |
2Ncp E Sophos2Ipsec Client Ncp Secure Entry ClientNov 21, 2024 Apr 9, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11...Show more |
1Pifzer 3Plum A+3 Infusion System Firmware Plum A+ Infusion System FirmwareSymbiq Infusion System FirmwareNov 21, 2024 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pump commands, and unau...Show more |
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization...Show more |