CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
658 vulnerabilities with CWE-345
CVE-2019-15613
HIGH
Nextcloud Server 17.0.1 - Insufficient Verification of Data Authenticity in Workflow Rules
CVSS 8.0
CVE-2019-20057
LOW
Proxyman < 1.11.0 - System Proxy Manipulation via Privileged Helper Tool
CVSS 3.7
CVE-2019-18829
HIGH
Barco ClickShare Button R9861500D01 <1.10.0.13 - Code Injection
CVSS 7.8
CVE-2019-18824
MEDIUM
Barco ClickShare Button R9861500D01 <1.10.0.13 - Info Disclosure
CVSS 6.6
CVE-2019-5291
MEDIUM
Huawei AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200 Firmware - Insufficient Verification of Data Authenticity
CVSS 5.9
CVE-2019-15971
MEDIUM
Cisco AsyncOS Software - Auth Bypass
CVSS 4.3
CVE-2019-2289
CRITICAL
Snapdragon Auto- Snapdragon Compute - Auth Bypass
CVSS 9.8
CVE-2019-5246
MEDIUM
ELLE-AL00B <9.1.0.162 - Privilege Escalation
CVSS 6.2
CVE-2019-5229
MEDIUM
P30 <ELLE-AL00B 9.1.0.193(C00E190R2P1 - Code Injection
CVSS 6.2
CVE-2019-18835
CRITICAL
Matrix Synapse <1.5.0 - Info Disclosure
CVSS 9.8
CVE-2019-8112
HIGH
Magento 2.2.0-2.2.9 and 2.3.0-2.3.2 - Unauthenticated Security Bypass via Email Confirmation Mechanism
CVSS 7.5
CVE-2019-3979
HIGH
MikroTik RouterOS < 6.44.5 and < 6.45.6 - DNS Cache Poisoning via Unrelated A Records
CVSS 7.5
CVE-2019-6475
MEDIUM
BIND 9.14.0-9.14.6 and 9.15.0-9.15.4 - DNSSEC Validation Bypass in Mirror Zone Feature
CVSS 5.9
CVE-2019-15162
MEDIUM
libpcap < 1.9.1 - Information Disclosure via Authentication Error Messages
CVSS 5.3
CVE-2019-10492
HIGH
Qualcomm Snapdragon Auto Mobile Wearables - Insufficient Boot Image Verification via AVB
CVSS 7.8
CVE-2019-11737
MEDIUM
Firefox < 69.0 - Content Security Policy Bypass via Wildcard Host
CVSS 5.3
CVE-2019-16398
MEDIUM
Keeper K5 <20.1.0.25-20.1.0.63 - RCE
CVSS 6.8
CVE-2019-12620
MEDIUM
Cisco HyperFlex HX220c/HX240c M5 Firmware - Unauthenticated Data Injection via Statistics Collection Service
CVSS 5.3
CVE-2019-5478
MEDIUM
AMD Zynq UltraScale+ Firmware - Insufficient Verification of Data Authenticity in Encrypt Only Boot Mode
CVSS 5.5
CVE-2019-6695
CRITICAL
FortiManager < 6.0.6 - Insufficient Verification of Data Authenticity
CVSS 9.8
CVE-2019-10943
HIGH
SIMATIC Drive Controller - Path Traversal
CVSS 7.5
CVE-2019-10181
HIGH
Icedtea-web <1.7.2, 1.8.2 - Code Injection
CVSS 8.1
CVE-2019-13483
HIGH
passport-sharepoint < 0.4.0 - Unauthenticated JWT Signature Forgery
CVSS 7.3
CVE-2019-12804
MEDIUM
Hunesion i-oneNet <4.0.16 - Code Injection
CVSS 5.5
CVE-2019-1932
MEDIUM
Cisco Advanced Malware Protection for Endpoints - Authenticated Remote Code Execution via Dynamically Loaded Module
CVSS 6.7
Details
Vulnerabilities
658