CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

656 vulnerabilities with CWE-345
CVE-2026-62995 LOW
joserfc accepts JWT with padding, leading to JWT malleability
CVE-2026-59247 HIGH
Insufficient verification of Hex package metadata in Gleam
CVE-2026-12383 HIGH
Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn
CVSS 7.5
CVE-2026-39155 MEDIUM
Knot DNS <3.4.10, 3.5.x<3.5.4: Authenticated DoS via NSEC Owner Name Miscalculation in mod-onlinesign
CVSS 6.5
CVE-2026-15615 HIGH
Logto - SAML <Conditions> Element Not Validated
CVSS 7.5
CVE-2026-15612 CRITICAL
Logto - LOIDC Nonce Validation Bypass
CVSS 9.1
CVE-2026-52688 HIGH
PowerDNS Recursor - DNSSEC Wildcard Validation Bypass
CVSS 7.5
CVE-2026-50248 MEDIUM
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVSS 6.5
CVE-2026-44690 HIGH
Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVSS 7.5
CVE-2026-13188 MEDIUM
DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 5.9
CVE-2026-62517 MEDIUM
Oracle Production Scheduling < 12.2.15 - Insufficient Verification of Data Authenticity
CVSS 5.3
CVE-2026-44584 MEDIUM
Paymenter doesn't reset email verification status after email change
CVSS 4.3
CVE-2026-12724 MEDIUM
Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
CVSS 4.3
CVE-2026-10724 MEDIUM
Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews
CVSS 4.8
CVE-2026-49284 HIGH
Simplesamlphp 2.4.7 and 2.5.0-rc1, < 2.5.2 - Information Disclosure
CVSS 7.1
CVE-2026-54496 CRITICAL
Zcash Orchard Action Circuit - Under-Constrained Base Point Proof Bypass
CVSS 9.3
CVE-2026-49212 HIGH
Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding
CVSS 7.5
CVE-2026-63094 HIGH
SigNoz 0.133.0 SSO OAuth State Manipulation Session Token Theft
CVSS 8.1
CVE-2026-62215 HIGH
OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas
CVSS 8.0
CVE-2026-44434 MEDIUM
Quicly is vulnerable to stateless reset injection
CVSS 5.3
CVE-2026-33731 MEDIUM
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
CVSS 6.5
CVE-2026-53536 MEDIUM
Activepieces: Cross-tenant file download via missing JWT audience check on step-files signed URL
CVE-2026-53516 HIGH
Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email
CVSS 8.3
CVE-2026-53514 HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-53513 CRITICAL
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
CVSS 9.6
Details
Vulnerabilities 656