CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
657 vulnerabilities with CWE-345
CVE-2026-9242
MEDIUM
RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request
CVSS 5.3
CVE-2026-55698
HIGH
pnpm < 10.34.2 and 11.0.0-11.5.2 - Lockfile-Selected Code Execution
CVSS 8.8
CVE-2026-50573
MEDIUM
pnpm: Unsafe default behavior breaks integrity check
CVSS 6.8
CVE-2026-52812
HIGH
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-45792
MEDIUM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
CVSS 5.5
CVE-2026-47155
MEDIUM
vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors
CVSS 6.5
CVE-2026-54288
MEDIUM
Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
CVSS 6.5
CVE-2026-54266
MEDIUM
Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
CVSS 6.1
CVE-2026-56073
CRITICAL
Cap-go - OTP Bypass via Response Manipulation in Email Verification
CVSS 9.4
CVE-2026-44087
CRITICAL
Apache APISIX: Openid-connect plugin Identity Header Spoofing
CVSS 9.1
CVE-2026-48783
MEDIUM
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
CVSS 4.8
CVE-2026-48781
CRITICAL
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVSS 9.9
CVE-2026-53862
MEDIUM
OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
CVSS 4.2
CVE-2026-53900
MEDIUM
Cookie injection was possible when opening a PDF link
CVSS 4.3
CVE-2026-53899
MEDIUM
Cross-origin cookies could be leaked when opening a PDF link
CVSS 6.5
CVE-2026-47777
HIGH
Mastodon has a consent-check bypass in its remote Collections
CVSS 7.5
CVE-2026-53406
HIGH
Zoom Communications Remote Control For Zoom Contact Center < 7.0.0 - Insufficient Verification of Data Authenticity
CVSS 7.8
CVE-2026-47691
HIGH
Netty has Insufficient Bailiwick Validation for NS Records
CVSS 8.7
CVE-2026-45674
HIGH
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CVSS 8.7
CVE-2026-46654
HIGH
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
CVE-2026-48096
MEDIUM
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
CVSS 5.0
CVE-2026-46539
MEDIUM
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
CVSS 5.9
CVE-2026-7792
MEDIUM
WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
CVSS 5.3
CVE-2026-8608
MEDIUM
Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action
CVSS 5.3
CVE-2026-50214
CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Shared Secret Quota Inflation
CVSS 9.8
Details
Vulnerabilities
657