CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
658 vulnerabilities with CWE-345
CVE-2024-2384
MEDIUM
WooCommerce POS <1.4.11 - Info Disclosure
CVSS 4.3
CVE-2024-27773
HIGH
Unitronics Unistream Unilogic <1.35.227 - RCE
CVSS 8.8
CVE-2024-28251
MEDIUM
Querybook < 3.32.0 - Cross-Site WebSocket Hijacking via CORS Misconfiguration
CVSS 5.6
CVE-2024-1321
MEDIUM
EventPrime - Events Calendar - Auth Bypass
CVSS 5.3
CVE-2024-27305
MEDIUM
aiosmtpd <1.4.5 - SMTP Smuggling Sender Spoofing
CVSS 5.3
CVE-2024-1554
CRITICAL
Firefox < 123.0 - Cache Poisoning via Fetch API Header Mismatch
CVSS 9.8
CVE-2024-24557
MEDIUM
Moby < 24.0.9 - Cache Poisoning via Classic Builder Cache System
CVSS 6.9
CVE-2023-28457
HIGH
Technitium DNS Server < 11.0.3 - DNS Cache Poisoning via Insufficient Response Verification
CVSS 7.5
CVE-2023-28865
MEDIUM
Diebold Nixdorf VSS <4.2.0 SR02 - Info Disclosure
CVSS 6.6
CVE-2023-6323
MEDIUM
ThroughTek Kalay SDK - Message Authenticity Bypass
CVSS 4.3
CVE-2023-45586
MEDIUM
Fortinet Fortiproxy < 2.0.12 - Data Authenticity Bypass
CVSS 5.0
CVE-2023-27360
HIGH
NETGEAR RAX30 Firmware < 1.0.10.94 - Unauthenticated Remote Code Execution via lighttpd Misconfiguration
CVSS 8.8
CVE-2023-6236
HIGH
Red Hat Enterprise Application Platform 8 - Privilege Escalation
CVSS 7.3
CVE-2023-52546
HIGH
Huawei EMUI - Insufficient Verification of Data Authenticity in Calendar App
CVSS 7.5
CVE-2023-35764
MEDIUM
Survey Maker < 3.6.4 - Unauthenticated IP Address Spoofing
CVSS 5.3
CVE-2023-20570
LOW
AMD Alveo and Kintex UltraScale Firmware - Insufficient Verification of Data Authenticity
CVSS 3.3
CVE-2023-32329
MEDIUM
IBM Security Verify Access 10.0.0.0-10.0.6.1 - Improper File Validation
CVSS 6.2
CVE-2023-52109
HIGH
Trust Relationship Inaccuracy - Info Disclosure
CVSS 7.5
CVE-2023-51766
MEDIUM
Exim < 4.97.1 - SMTP Smuggling via LF.CR.LF Sequence
CVSS 5.3
CVE-2023-51765
MEDIUM
sendmail < 8.18.0.2 - SMTP Smuggling via LF.CR.LF Sequence
CVSS 5.3
CVE-2023-51764
MEDIUM
Postfix < 3.5.23 - SMTP Smuggling via Bare Newline Injection
CVSS 5.3
CVE-2023-51655
MEDIUM
JetBrains IntelliJ IDEA <2023.3.2 - RCE
CVSS 6.3
CVE-2023-45292
MEDIUM
mojotv/base64captcha < 1.3.6 - Insufficient Verification of Data Authenticity in Verify Function
CVSS 5.3
CVE-2023-44402
MEDIUM
Electron < 22.3.24 - Insufficient Verification of Data Authenticity via Asar Integrity Validation Bypass
CVSS 6.1
CVE-2023-49087
MEDIUM
simplesamlphp/saml2 5.0.0-alpha.12 - Insufficient Verification of Data Authenticity in XML Signature Validation
CVSS 6.8
Details
Vulnerabilities
658