CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

658 vulnerabilities with CWE-345
CVE-2021-20267 HIGH
OpenStack Neutron < 16.3.3 - IPv6 Spoofing via Open vSwitch Firewall Rules
CVSS 7.1
CVE-2021-22339 MEDIUM
Huawei ManageOne - Denial of Service via Insufficient Parameter Verification
CVSS 6.5
CVE-2021-30005 HIGH
JetBrains PyCharm < 2020.3.4 - Local Code Execution via VCS Project Import
CVSS 7.8
CVE-2021-29239 HIGH
CODESYS Development System 3 < 3.5.17.0 - Insufficient Verification of Data Authenticity
CVSS 7.8
CVE-2021-31783 HIGH
LocalFilesEditor < 11.4.0.1 - Local File Inclusion via show_default.php file Parameter
CVSS 7.5
CVE-2021-29462 HIGH
pupnp < 1.14.6 - DNS Rebinding Attack via Missing Host Header Validation
CVSS 7.6
CVE-2021-20271 HIGH
rpm 4.15.0-4.15.1.3 - Remote Code Execution via Modified Signature Header
CVSS 7.0
CVE-2021-1403 HIGH
Cisco IOS XE - Unauthenticated Cross-Site WebSocket Hijacking and Denial of Service via Crafted Link
CVSS 7.4
CVE-2021-21320 LOW
matrix-react-sdk < 3.15.0 - Insufficient Verification of Data Authenticity
CVSS 2.6
CVE-2021-3349 LOW
GNOME Evolution < 3.38.3 - Insufficient Verification of Data Authenticity via GnuPG API
CVSS 3.3
CVE-2020-1755 MEDIUM
Moodle <3.8.2, <3.7.5, <3.6.9, <3.5.11 - CSRF
CVSS 5.3
CVE-2020-14122 MEDIUM
MIUI - Information Leakage and Identity Forgery via Insufficient Parameter Verification
CVSS 5.5
CVE-2020-14116 HIGH
Mi Browser < 15.8.0 - Intent Redirection via Unverified Data
CVSS 7.5
CVE-2020-14115 CRITICAL
Xiaomi Router AX3600 < 1.0.67 - OS Command Injection
CVSS 9.8
CVE-2020-14111 HIGH
Xiaomi Router AX3600 < 1.1.15 - OS Command Injection
CVSS 7.8
CVE-2020-10137 MEDIUM
Silabs Uzb-7 - Data Authenticity Bypass
CVSS 6.5
CVE-2020-7878 CRITICAL
4nb VideoOffice < x2.9 - Arbitrary File Download and Execution
CVSS 9.8
CVE-2020-23906 MEDIUM
FFmpeg N-98388-g76a3ee996b - Denial of Service via Crafted Audio File
CVSS 5.5
CVE-2020-24672 CRITICAL
Base Software for SoftControl - Code Injection
CVSS 9.8
CVE-2020-19769 HIGH
rtb1 - Insufficient Verification of Data Authenticity in BurnMe() Function
CVSS 7.5
CVE-2020-19768 HIGH
tokensale - Insufficient Verification of Data Authenticity in selfdestructs() Function
CVSS 7.5
CVE-2020-28900 CRITICAL
Nagios Fusion < 4.1.8 and Nagios XI < 5.7.5 - Privilege Escalation and Code Execution via Untrusted Update Package
CVSS 9.8
CVE-2020-24395 MEDIUM
homee Brain Cube <2.28.4 - Code Injection
CVSS 6.8
CVE-2020-26547 CRITICAL
Monal < 4.9 - Message Spoofing via MAM and Message Carbon Results
CVSS 9.8
CVE-2020-9141 CRITICAL
Huawei EMUI and Magic UI - Improper Privilege Management
CVSS 9.1
Details
Vulnerabilities 658