CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
658 vulnerabilities with CWE-345
CVE-2020-16122
HIGH
PackageKit - Improper Privilege Management via APT Backend
CVSS 8.2
CVE-2020-27670
HIGH
Xen <4.14.x - DoS/Privilege Escalation
CVSS 7.8
CVE-2020-15262
LOW
Webpack-subresource-integrity <1.5.1 - Info Disclosure
CVSS 3.7
CVE-2020-1677
HIGH
Juniper Mist Cloud UI < 2020-09-02 - SAML Authentication Bypass via Modified SAML Response
CVSS 7.2
CVE-2020-9885
MEDIUM
iPadOS < 13.6 - Insufficient Verification of iMessage Tapbacks
CVSS 5.5
CVE-2020-26893
HIGH
ClamXAV <3.1.1 - Privilege Escalation
CVSS 7.8
CVE-2020-9230
MEDIUM
WS5800-10 Firmware 10.0.3.25 - Denial of Service via Improper Message Verification
CVSS 6.5
CVE-2020-15222
HIGH
ORY Fosite <0.31.0 - Info Disclosure
CVSS 8.1
CVE-2020-24045
HIGH
TitanHQ SpamTitan Gateway 7.07 - Sandbox Escape via Fake VMware Tools ISO Image
CVSS 7.2
CVE-2020-15163
HIGH
Python TUF < 0.12.0 - Insufficient Verification of Data Authenticity
CVSS 8.7
CVE-2020-11493
HIGH
Foxit PhantomPDF < 9.7.3 and Reader < 10.0.1 - Information Disclosure via Crafted XObject
CVSS 8.1
CVE-2020-25019
HIGH
jitsi-meet-electron < 2.3.0 - Unauthenticated Arbitrary URL Execution via shell.openExternal
CVSS 7.5
CVE-2020-16250
HIGH
HashiCorp Vault 0.7.1-1.2.4 - Authentication Bypass via AWS IAM Auth Method
CVSS 8.2
CVE-2020-13178
MEDIUM
Teradici PCoIP Standard Agent <20.04.1 - Privilege Escalation
CVSS 6.7
CVE-2020-11985
MEDIUM
Apache HTTP Server 2.4.1-2.4.23 - IP Address Spoofing via mod_remoteip and mod_rewrite
CVSS 5.3
CVE-2020-15899
HIGH
Grin 3.0.0-3.1.1 - Insufficient Verification of Data Authenticity
CVSS 7.5
CVE-2020-15699
MEDIUM
Joomla! 2.5.0-3.9.19 - Insufficient Verification of Data Authenticity in Usergroups Table
CVSS 5.3
CVE-2020-12406
HIGH
Firefox < 77.0 - Memory Corruption via Unboxed Object Type Confusion
CVSS 8.8
CVE-2020-12119
HIGH
Ledger Live < 2.7.0 - Insufficient Verification of Data Authenticity in Bitcoin RBF Handling
CVSS 8.1
CVE-2020-5964
HIGH
NVIDIA Windows GPU Display Driver - Code Execution
CVSS 7.8
CVE-2020-13272
HIGH
OAuth flow - Unverified User Access
CVSS 7.5
CVE-2020-13265
MEDIUM
GitLab 12.5.0-13.0.1 - Email Verification Bypass
CVSS 4.3
CVE-2020-14453
HIGH
Mattermost Server < 5.21.0 - Denial of Service via Socket Read Operations
CVSS 7.5
CVE-2020-11614
HIGH
Mids' Reborn Hero Designer 2.6.0.7 - Cleartext Transmission of Sensitive Information via HTTP Update Manifest
CVSS 8.1
CVE-2020-6090
HIGH
WAGO PFC 200 03.03.10(15) - Authenticated Remote Code Execution via Web-Based Management
CVSS 7.2
Details
Vulnerabilities
658