CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
658 vulnerabilities with CWE-345
CVE-2023-26467
MEDIUM
Pega Synchronization Engine 3.1.1-3.1.29 - Man-in-the-Middle Traffic Redirection via Compromised Configuration
CVSS 5.4
CVE-2023-27979
MEDIUM
Schneider Electric IGSS < 16.0.0.23040 - DoS via Crafted TCP Messages
CVSS 6.5
CVE-2023-27977
MEDIUM
Schneider Electric IGSS < 16.0.0.23040 - Unauthenticated File Deletion via TCP
CVSS 6.5
CVE-2023-27982
HIGH
Schneider Electric IGSS < 16.0.0.23040 - Remote Code Execution via TCP
CVSS 8.8
CVE-2023-0350
MEDIUM
Akuvox E11 - Insufficient File Extension Verification
CVSS 6.5
CVE-2023-26481
CRITICAL
authentik < 2022.12.3 - Unauthenticated Password Reset via Recovery Flow Token
CVSS 9.1
CVE-2023-21441
HIGH
Samsung Android Routine < 2.6.30.6 (Q), < 3.1.21.10 (R), < 3.5.2.23 (S) - Insufficient Verification of Data Authenticity
CVSS 7.4
CVE-2023-23941
HIGH
SwagPayPal <5.4.4 - Info Disclosure
CVSS 7.5
CVE-2023-23940
MEDIUM
OpenZeppelin Contracts for Cairo - Code Injection
CVSS 6.4
CVE-2023-22315
MEDIUM
Snap One Wattbox WB-300-IP-3 <WB10.9a17 - Code Injection
CVSS 6.7
CVE-2022-4992
HIGH
Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering
CVSS 8.6
CVE-2022-33861
MEDIUM
Eaton Intelligent Power Protector < 1.71 - Insufficient Verification of Data Authenticity
CVSS 5.1
CVE-2022-4533
MEDIUM
Limit Login Attempts Plus <1.1.0 - SSRF
CVSS 5.3
CVE-2022-4539
MEDIUM
WordPress Web Application Firewall <= 2.1.2 - X-Forwarded-For IP Spoofing
CVSS 5.3
CVE-2022-44593
LOW
SolidWP Solid Security < 9.3.1 - Denial of Service via IP Spoofing
CVSS 3.7
CVE-2022-4537
MEDIUM
Hide My WP Ghost - Security Plugin <5.0.18 - Info Disclosure
CVSS 6.5
CVE-2022-44420
MEDIUM
Android - Denial of Service via Missing HashMME Verification in Security Mode Command
CVSS 5.5
CVE-2022-48431
MEDIUM
JetBrains IntelliJ IDEA < 2023.1 - Insufficient Verification of Data Authenticity
CVSS 4.5
CVE-2022-46370
HIGH
Rumpus < 9.0.7.1 - Improper Token Verification
CVSS 7.3
CVE-2022-42267
HIGH
NVIDIA Virtual GPU < 11.11 - Out-of-Bounds Read
CVSS 7.0
CVE-2022-3347
HIGH
go-resolver - DNSSEC Validation Bypass
CVSS 7.5
CVE-2022-3346
MEDIUM
go-resolver - RRSIG Owner Name DNSSEC Validation Bypass
CVSS 6.5
CVE-2022-30260
HIGH
Emerson DeltaV Distributed Control System < 14.3 - Insufficient Firmware Integrity Verification
CVSS 7.8
CVE-2022-36315
MEDIUM
Firefox < 103.0 - Insufficient Verification of Data Authenticity via Cached Script Reuse
CVSS 4.3
CVE-2022-34471
MEDIUM
Firefox < 102.0 - Addon Downgrade via Manifest Version Mismatch
CVSS 6.5
Details
Vulnerabilities
658