CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
658 vulnerabilities with CWE-345
CVE-2019-3875
MEDIUM
Keycloak < 6.0.2 - Improper Certificate Validation in X.509 Authenticator
CVSS 6.5
CVE-2019-10157
MEDIUM
Keycloak's Node.js adapter <4.8.3 - Privilege Escalation
CVSS 4.7
CVE-2019-1880
MEDIUM
Cisco UCS C-Series Rack Servers - Privilege Escalation
CVSS 4.4
CVE-2019-5587
MEDIUM
Fortinet FortiOS < 6.0.5 - Unauthenticated Malicious Image Implantation via Root File System Integrity Bypass
CVSS 6.5
CVE-2019-5431
MEDIUM
Twitter Kit for iOS <3.4.0 - Callback Verification Flaw
CVSS 5.4
CVE-2019-3786
HIGH
Cloud Foundry BOSH Backup and Restore CLI < 1.5.0 - Authenticated Privilege Escalation via Backup Script Metadata
CVSS 7.1
CVE-2019-11235
CRITICAL
FreeRADIUS < 3.0.19 - Insufficient Verification of Data Authenticity
CVSS 9.8
CVE-2019-0805
HIGH
Windows - Elevation of Privilege via LUAFV Driver Calls
CVSS 7.8
CVE-2019-1667
LOW
Cisco HyperFlex HX Data Platform < 3.5(2a) - Authenticated Arbitrary Data Write via Graphite Interface
CVSS 3.3
CVE-2019-1000013
HIGH
Hex package manager <0.3.0 - Code Execution
CVSS 8.8
CVE-2019-1000012
HIGH
Hex package manager <0.19 - Code Execution
CVSS 8.8
CVE-2019-7323
HIGH
LightySoft LogMX <7.4.0 - Code Injection
CVSS 7.5
CVE-2019-3807
LOW
PowerDNS Recursor 4.1.0-4.1.8 - Improper Certificate Validation
CVSS 3.7
CVE-2018-17287
MEDIUM
Kofax Front Office Server Administration Console 4.1.1.11.0.5212 - Information Disclosure via Download Feature
CVSS 4.9
CVE-2018-19971
CRITICAL
JFrog Artifactory Pro 6.5.9 - Privilege Escalation
CVSS 9.8
CVE-2018-15801
HIGH
Spring Security 5.1.x < 5.1.2 - Authorization Bypass via JWT Issuer Validation
CVSS 7.4
CVE-2018-7798
HIGH
Modicon M221 - Info Disclosure
CVSS 8.2
CVE-2018-17938
MEDIUM
Zimbra Collaboration Suite < 8.8.10 - Text Content Spoofing via loginErrorCode
CVSS 5.3
CVE-2018-10626
MEDIUM
Medtronic MyCareLink - Info Disclosure
CVSS 4.4
CVE-2018-10894
MEDIUM
Keycloak - Improper Certificate Validation in SAML Authentication
CVSS 5.4
CVE-2018-2434
MEDIUM
SAP NetWeaver UI Add-on and SAP UI Implementation - Content Spoofing via HTML Page Rendering
CVSS 4.3
CVE-2018-12333
HIGH
ECOS Secure Boot Stick <5.6.5 - Code Injection
CVSS 8.1
CVE-2018-6562
HIGH
totemomail Encryption Gateway < 6.0.0_b567 - Information Disclosure via JSONP Hijacking
CVSS 7.5
CVE-2018-7932
HIGH
Huawei AppGallery < 8.0.4.301 - Arbitrary JavaScript Execution via Whitelist Bypass
CVSS 8.8
CVE-2018-10080
HIGH
Secutech RiS-11, RiS-22, RiS-33 <5.07.52_es_FRI01 - CSRF
CVSS 8.6
Details
Vulnerabilities
658