CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
656 vulnerabilities with CWE-345
CVE-2026-62995
LOW
joserfc accepts JWT with padding, leading to JWT malleability
CVE-2026-59247
HIGH
Insufficient verification of Hex package metadata in Gleam
CVE-2026-12383
HIGH
Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn
CVSS 7.5
CVE-2026-39155
MEDIUM
Knot DNS <3.4.10, 3.5.x<3.5.4: Authenticated DoS via NSEC Owner Name Miscalculation in mod-onlinesign
CVSS 6.5
CVE-2026-15615
HIGH
Logto - SAML <Conditions> Element Not Validated
CVSS 7.5
CVE-2026-15612
CRITICAL
Logto - LOIDC Nonce Validation Bypass
CVSS 9.1
CVE-2026-52688
HIGH
PowerDNS Recursor - DNSSEC Wildcard Validation Bypass
CVSS 7.5
CVE-2026-50248
MEDIUM
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVSS 6.5
CVE-2026-44690
HIGH
Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVSS 7.5
CVE-2026-13188
MEDIUM
DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 5.9
CVE-2026-62517
MEDIUM
Oracle Production Scheduling < 12.2.15 - Insufficient Verification of Data Authenticity
CVSS 5.3
CVE-2026-44584
MEDIUM
Paymenter doesn't reset email verification status after email change
CVSS 4.3
CVE-2026-12724
MEDIUM
Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
CVSS 4.3
CVE-2026-10724
MEDIUM
Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews
CVSS 4.8
CVE-2026-49284
HIGH
Simplesamlphp 2.4.7 and 2.5.0-rc1, < 2.5.2 - Information Disclosure
CVSS 7.1
CVE-2026-54496
CRITICAL
Zcash Orchard Action Circuit - Under-Constrained Base Point Proof Bypass
CVSS 9.3
CVE-2026-49212
HIGH
Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding
CVSS 7.5
CVE-2026-63094
HIGH
SigNoz 0.133.0 SSO OAuth State Manipulation Session Token Theft
CVSS 8.1
CVE-2026-62215
HIGH
OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas
CVSS 8.0
CVE-2026-44434
MEDIUM
Quicly is vulnerable to stateless reset injection
CVSS 5.3
CVE-2026-33731
MEDIUM
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
CVSS 6.5
CVE-2026-53536
MEDIUM
Activepieces: Cross-tenant file download via missing JWT audience check on step-files signed URL
CVE-2026-53516
HIGH
Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email
CVSS 8.3
CVE-2026-53514
HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-53513
CRITICAL
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
CVSS 9.6
Details
Vulnerabilities
656